Threat reportSupply ChainTL-2026-0034

GlassWorm macOS Attack via Compromised OpenVSX Extensions

highMONITORING

GlassWorm macOS Attack via Compromised OpenVSX Extensions (TL-2026-0034), also tracked as GlassWorm macOS, is a high-severity supply-chain compromise scored CVSS 8.1, first published 2026-02-03. It is attributed to GlassWorm with high confidence, affects Multiple VS Code with OpenVSX extensions on macOS, maps to 31 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 12 detection rules and 40 indicators of compromise.

CVSS
8.1/10High
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
1GlassWorm
Detection rules
12SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-0034

Threat ID
TL-2026-0034
Also known as
GlassWorm macOS, OpenVSX Supply Chain, VS Code macOS Malware
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
MONITORING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
GlassWorm
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
Technology, Software Development, Cryptocurrency, Financial Services, SaaS Providers
Target regions
Global
Detection rules
12
Indicators of compromise
40

Malware and tooling in GlassWorm macOS Attack via Compromised OpenVSX Extensions

Malware and tooling: GlassWorm

How GlassWorm macOS Attack via Compromised OpenVSX Extensions works

GlassWorm is a macOS-targeting malware family distributed through compromised and typosquatted extensions on the OpenVSX marketplace — the open-source alternative to Microsoft's Visual Studio Code Marketplace. Unlike traditional software supply chain attacks that compromise build systems or package registries, GlassWorm exploits the unique trust model of IDE extensions: extensions execute with the full privileges of the developer's user account, with no sandboxing, no permission model, and full access to the filesystem, SSH keys, Git credentials, cloud tokens, macOS Keychain, cryptocurrency wallets, and every file the developer can touch. The attack targets macOS developers specifically, leveraging macOS-specific persistence mechanisms (LaunchAgents, Login Items) and credential stores (Keychain Access, Safari cookies, Homebrew tokens). OpenVSX's governance model — community-maintained with limited vetting — creates a softer target than Microsoft's Marketplace, which itself has demonstrated inadequate review processes (Aqua Nautilus POC: 1,000+ installs in 48 hours for a masquerading Prettier extension). GlassWorm represents the convergence of three attack vectors: IDE extension supply chain, macOS credential theft, and open-source marketplace trust exploitation. The developer's IDE IS the attack surface — extensions have god-mode access to everything the developer touches, and the marketplace verification model provides false assurance of safety.

GlassWorm targets the developer workstation through the most trusted application in a developer's workflow: their IDE. Visual Studio Code (74.48% developer market share per StackOverflow) supports 40,000+ extensions, and the OpenVSX registry provides the open-source alternative used by VS Code forks (VSCodium, Gitpod, Eclipse Theia, code-server). GlassWorm exploits this ecosystem through multiple delivery vectors:

DELIVERY VECTORS:

1. TYPOSQUATTED EXTENSIONS: GlassWorm operators create extensions with names nearly identical to popular packages — single character substitutions (esbenp→espenp, prettier-vscode→pretier-vscode). The VSCode/OpenVSX marketplace allows identical displayNames for publishers and extensions, enabling perfect visual impersonation. Developers searching for popular tools accidentally install malicious versions.

2. COMPROMISED LEGITIMATE EXTENSIONS: GlassWorm actors compromise existing extension publisher accounts via credential theft or social engineering, then push malicious updates to extensions with established install bases. Existing users receive the malicious update automatically. This is the most dangerous vector — the extension was previously legitimate.

3. BACKDOORED FORKS: Popular extensions are forked on GitHub, GlassWorm payload is inserted, and the fork is published to OpenVSX as an 'improved' or 'community' version. The open-source nature of OpenVSX makes this trivial — anyone can publish.

VS CODE EXTENSION TRUST MODEL (THE ROOT VULNERABILITY):

VS Code extensions execute with ZERO sandboxing. Aqua Nautilus research confirmed: - Extensions run with the full privileges of the user who launched VS Code - No permission model exists — extensions can access ANY file, network resource, or process - Extensions can install additional software (ransomware, wipers, backdoors) - Extensions can read and modify ALL local code repositories - Extensions can use SSH keys to push code to remote repositories (GitHub, GitLab) - Extensions execute on every VS Code startup via the 'activate' function - The 'verified publisher' badge means only domain ownership — NOT identity verification or code review

OPENVSX vs MICROSOFT MARKETPLACE:

OpenVSX is the open-source, community-maintained VS Code extension registry: - Governance: Eclipse Foundation stewardship, community moderation (vs Microsoft's centralized review) - Publishing: Any GitHub/Eclipse account holder can publish (lower barrier than Microsoft Marketplace) - Review process: Automated scanning for known malware signatures, limited manual review - Protections: Less typosquatting protection than Microsoft Marketplace (which itself is inadequate) - Users: VSCodium, Gitpod, Eclipse Theia, code-server, OpenVSCode Server — millions of developers - Trust assumption: Developers assume OpenVSX extensions are vetted similarly to npm/PyPI — they are not

Microsoft Marketplace weaknesses (Aqua Nautilus POC): - 1,000+ installs in 48 hours for a masquerading Prettier extension - displayName allows exact replication of legitimate extension names - 'Verified' badge means domain ownership only — any attacker can verify a domain - GitHub repository links are unvalidated — extensions can claim any repo - No protection against typosquatting except for Microsoft/Red Hat official extensions - Anonymous registration allowed (temporary email sufficient)

OpenVSX has fewer protections than even this inadequate baseline.

GLASSWORM MALWARE CAPABILITIES (macOS-SPECIFIC):

1. CREDENTIAL THEFT: - macOS Keychain Access: Extracts stored passwords, certificates, and tokens using security CLI or Keychain API - Browser credentials: Safari cookies/passwords, Chrome/Brave/Firefox credential stores - SSH keys: ~/.ssh/ directory — private keys for GitHub, server access, cloud infrastructure - Git credentials: ~/.gitconfig, credential helpers, GitHub/GitLab personal access tokens - Cloud tokens: AWS credentials (~/.aws/), GCP service account keys, Azure CLI tokens - IDE tokens: VS Code settings.json containing API keys, extension auth tokens - Homebrew tokens: GitHub tokens stored in Homebrew configuration

2. CRYPTOCURRENCY WALLET TARGETING: - Exodus, Electrum, MetaMask (browser extension), Phantom, Ledger Live desktop app - Wallet files, seed phrases, private keys in macOS Keychain or application data - Clipboard monitoring for cryptocurrency addresses (address substitution)

3. macOS-SPECIFIC PERSISTENCE: - LaunchAgents: ~/Library/LaunchAgents/ — user-level persistence surviving reboot - LaunchDaemons: /Library/LaunchDaemons/ (requires elevation) — system-level persistence - Login Items: ~/Library/Preferences/ com.apple.loginitems.plist - Periodic scripts: /usr/local/etc/periodic/ for scheduled execution - VS Code extension auto-update: malicious extension persists through IDE restarts - Gatekeeper bypass: unsigned code loaded as VS Code extension subprocess avoids Gatekeeper checks because VS Code itself is signed/notarized

4. DATA EXFILTRATION: - Source code repositories: git clone of all local repos to attacker C2 - Environment variables: contains API keys, database URLs, secrets - .env files: development secrets in project directories - Docker configurations: docker-compose.yml with database credentials - Kubernetes configs: ~/.kube/config with cluster access tokens

GATEKEEPER BYPASS MECHANISM:

macOS Gatekeeper validates that applications are signed and notarized by Apple. VS Code itself passes Gatekeeper validation (signed by Microsoft). Extensions loaded BY VS Code execute as child processes of the signed VS Code application — Gatekeeper does not independently validate extension code. This means: - GlassWorm code runs with full user privileges - macOS does not prompt the user about unsigned code - XProtect malware scanning may not inspect VS Code extension directories - The extension inherits VS Code's TCC (Transparency, Consent, and Control) permissions - If the developer granted VS Code Full Disk Access, GlassWorm inherits it

IMPACT CHAIN:

Single compromised developer workstation → SSH keys → GitHub org access → production deployment keys → cloud infrastructure → customer data. The developer's machine is the nexus of maximum credential concentration.

MITRE ATT&CK techniques used in TL-2026-0034

collection

T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data; T1213 Data from Information Repositories; T1530 Data from Cloud Storage

lateral-movement

T1021 Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution; T1550 Use Alternate Authentication Material

exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

discovery

T1082 System Information Discovery; T1518 Software Discovery

initial-access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

credential-access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

privilege-escalation

T1546 Event Triggered Execution

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

resource-development

T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities

reconnaissance

T1591 Gather Victim Org Information

impact

T1657 Financial Theft

Affected products and versions in GlassWorm macOS Attack via Compromised OpenVSX Extensions

  • Multiple — VS Code with OpenVSX extensions on macOS
    Vulnerable versions: macOS users with compromised extensions
    Fixed in: Remove malicious extensions

Remediation for GlassWorm macOS Attack via Compromised OpenVSX Extensions

Immediate actions

  • Audit installed VS Code extensions on all macOS developer machines
  • Remove any extensions from unknown or compromised publishers
  • Check ~/Library/LaunchAgents for suspicious .plist files
  • Rotate all credentials that may have been exposed (SSH keys, API tokens, AWS credentials)
  • Check cryptocurrency wallets for unauthorized transactions

Workarounds

  • Disable automatic extension updates
  • Review extension permissions before installation
  • Use VS Code in a containerized environment for sensitive work

Longer-term hardening

  • Implement extension allowlisting in VS Code settings
  • Use official VS Code Marketplace instead of OpenVSX where possible
  • Deploy EDR with macOS-specific detection rules
  • Enable macOS System Integrity Protection (SIP)
  • Regular audits of LaunchAgents and LaunchDaemons

Weaknesses (CWE) in GlassWorm macOS Attack via Compromised OpenVSX Extensions

CWE-494, CWE-829

Timeline of GlassWorm macOS Attack via Compromised OpenVSX Extensions

  • Microsoft launches Visual Studio Code as open-source cross-platform IDE. Extension marketplace enables third-party functionality. Extensions execute with full user privileges — no sandboxing from day one. This architectural decision enables the entire GlassWorm threat class.
  • Eclipse Foundation launches OpenVSX Registry as open-source alternative to Microsoft's VS Code Marketplace. Used by VSCodium, Gitpod, Eclipse Theia. Community-governed with lower publishing barriers than Microsoft Marketplace. Creates additional attack surface for IDE extension supply chain attacks.
  • First documented malicious VS Code extensions discovered in Microsoft Marketplace. Extensions with eval()-based remote code execution (robotnowai.top C2), HTTP-based command retrieval, and hostname exfiltration. Reported to Microsoft. Demonstrates the attack surface exists and is actively exploited.
  • Snyk publishes deep dive on VS Code extension security vulnerabilities. Documents extension privilege model: full user-level access, no sandbox, no permission model. Identifies credential theft, code modification, and lateral movement risks from malicious extensions.
  • Aqua Nautilus publishes groundbreaking VS Code Marketplace security research. POC masquerading Prettier extension achieves 1,000+ installs in 48 hours. Demonstrates: displayName allows exact impersonation, 'verified' badge means only domain ownership, GitHub repo links are unvalidated, anonymous registration possible. Source: Aqua Nautilus
  • GlassWorm malware family identified targeting macOS developers via compromised OpenVSX extensions. Capabilities: macOS Keychain theft, SSH key exfiltration, cryptocurrency wallet targeting, LaunchAgent persistence. Exploits Gatekeeper bypass — extension code inherits VS Code's signed application trust.
  • GlassWorm evolves with enhanced macOS-specific capabilities: Keychain Access API integration for credential extraction, Login Items persistence, TCC permission inheritance from VS Code, Safari cookie theft. Targets developer concentration of credentials: SSH + Git + cloud tokens + API keys on single machine.
  • GlassWorm adds cryptocurrency wallet targeting: Exodus, Electrum, MetaMask, Phantom wallet files and seed phrases. Clipboard monitoring for crypto address substitution. Developer machines are high-value targets — developers are disproportionately likely to hold cryptocurrency.
  • Security researchers document OpenVSX governance gaps: limited automated scanning, no code review requirement, minimal typosquatting protection, reliance on community reporting for malicious extensions. Publishing an extension requires only a GitHub or Eclipse account — no identity verification.
  • GlassWorm operators compromise legitimate extension publisher accounts to push malicious updates to extensions with established install bases. Automatic extension updates deliver GlassWorm to all existing users without interaction. The trust relationship with legitimate extensions is weaponized.
  • VS Code community proposes extension sandboxing API modeled on browser extension permissions. Extensions would declare required permissions (filesystem, network, credentials). Users would approve permissions at install time. Implementation remains in proposal stage — the attack surface persists.
  • Current state: VS Code extensions remain fully unsandboxed. OpenVSX governance provides less protection than Microsoft Marketplace (which is itself inadequate). GlassWorm actively targets macOS developers via typosquatted and compromised extensions. Developer machines concentrate the highest-value credentials in any organization.
  • As of 2026-05-29, GlassWorm's botnet was disrupted on May 26 when CrowdStrike, Google, and Shadowserver simultaneously severed all four C2 channels (Solana, BitTorrent DHT, Google Calendar, VPS), halting propagation and payload delivery. It is not resolved: operators remain unapprehended and capable (April 2026 saw 73 new OpenVSX sleeper extensions), and infected hosts still require remediation, so monitoring continues.

Sources cited for GlassWorm macOS Attack via Compromised OpenVSX Extensions

Detection coverage for TL-2026-0034

As of 2026-02-03, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0034 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats