# GlassWorm macOS Attack via Compromised OpenVSX Extensions

> GlassWorm is a macOS-targeting malware family distributed through compromised and typosquatted extensions on the OpenVSX marketplace — the open-source alternative to Microsoft's Visual Studio Code Marketplace. Unlike traditional software supply chain attacks that compromise build systems or package registries, GlassWorm exploits the unique trust model of IDE extensions: extensions execute with the full privileges of the developer's user account, with no sandboxing, no permission model, and full access to the filesystem, SSH keys, Git credentials, cloud tokens, macOS Keychain, cryptocurrency wallets, and every file the developer can touch. The attack targets macOS developers specifically, leveraging macOS-specific persistence mechanisms (LaunchAgents, Login Items) and credential stores (Keychain Access, Safari cookies, Homebrew tokens). OpenVSX's governance model — community-maintained with limited vetting — creates a softer target than Microsoft's Marketplace, which itself has demonstrated inadequate review processes (Aqua Nautilus POC: 1,000+ installs in 48 hours for a masquerading Prettier extension). GlassWorm represents the convergence of three attack vectors: IDE extension supply chain, macOS credential theft, and open-source marketplace trust exploitation. The developer's IDE IS the attack surface — extensions have god-mode access to everything the developer touches, and the marketplace verification model provides false assurance of safety.

- **Published:** 2026-02-03T00:40:00Z
- **Last reviewed:** 2026-02-03T00:40:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0034
- **ID:** TL-2026-0034
- **Severity:** HIGH (CVSS 8.1)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Actor:** GlassWorm
- **Detections:** 12 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GlassWorm targets the developer workstation through the most trusted application in a developer's workflow: their IDE. Visual Studio Code (74.48% developer market share per StackOverflow) supports 40,000+ extensions, and the OpenVSX registry provides the open-source alternative used by VS Code forks (VSCodium, Gitpod, Eclipse Theia, code-server). GlassWorm exploits this ecosystem through multiple delivery vectors:

DELIVERY VECTORS:

1. TYPOSQUATTED EXTENSIONS: GlassWorm operators create extensions with names nearly identical to popular packages — single character substitutions (esbenp→espenp, prettier-vscode→pretier-vscode). The VSCode/OpenVSX marketplace allows identical displayNames for publishers and extensions, enabling perfect visual impersonation. Developers searching for popular tools accidentally install malicious versions.

2. COMPROMISED LEGITIMATE EXTENSIONS: GlassWorm actors compromise existing extension publisher accounts via credential theft or social engineering, then push malicious updates to extensions with established install bases. Existing users receive the malicious update automatically. This is the most dangerous vector — the extension was previously legitimate.

3. BACKDOORED FORKS: Popular extensions are forked on GitHub, GlassWorm payload is inserted, and the fork is published to OpenVSX as an 'improved' or 'community' version. The open-source nature of OpenVSX makes this trivial — anyone can publish.

VS CODE EXTENSION TRUST MODEL (THE ROOT VULNERABILITY):

VS Code extensions execute with ZERO sandboxing. Aqua Nautilus research confirmed:
- Extensions run with the full privileges of the user who launched VS Code
- No permission model exists — extensions can access ANY file, network resource, or process
- Extensions can install additional software (ransomware, wipers, backdoors)
- Extensions can read and modify ALL local code repositories
- Extensions can use SSH keys to push code to remote repositories (GitHub, GitLab)
- Extensions execute on every VS Code startup via the 'activate' function
- The 'verified publisher' badge means only domain ownership — NOT identity verification or code review

OPENVSX vs MICROSOFT MARKETPLACE:

OpenVSX is the open-source, community-maintained VS Code extension registry:
- Governance: Eclipse Foundation stewardship, community moderation (vs Microsoft's centralized review)
- Publishing: Any GitHub/Eclipse account holder can publish (lower barrier than Microsoft Marketplace)
- Review process: Automated scanning for known malware signatures, limited manual review
- Protections: Less typosquatting protection than Microsoft Marketplace (which itself is inadequate)
- Users: VSCodium, Gitpod, Eclipse Theia, code-server, OpenVSCode Server — millions of developers
- Trust assumption: Developers assume OpenVSX extensions are vetted similarly to npm/PyPI — they are not

Microsoft Marketplace weaknesses (Aqua Nautilus POC):
- 1,000+ installs in 48 hours for a masquerading Prettier extension
- displayName allows exact replication of legitimate extension names
- 'Verified' badge means domain ownership only — any attacker can verify a domain
- GitHub repository links are unvalidated — extensions can claim any repo
- No protection against typosquatting except for Microsoft/Red Hat official extensions
- Anonymous registration allowed (temporary email sufficient)

OpenVSX has fewer protections than even this inadequate baseline.

GLASSWORM MALWARE CAPABILITIES (macOS-SPECIFIC):

1. CREDENTIAL THEFT:
   - macOS Keychain Access: Extracts stored passwords, certificates, and tokens using security CLI or Keychain API
   - Browser credentials: Safari cookies/passwords, Chrome/Brave/Firefox credential stores
   - SSH keys: ~/.ssh/ directory — private keys for GitHub, server access, cloud infrastructure
   - Git credentials: ~/.gitconfig, credential helpers, GitHub/GitLab personal access tokens
   - Cloud tokens: AWS credentials (~/.aws/), GCP service account keys, Azure CLI tokens
   - IDE tokens: VS Code settings.json containing API keys, extension auth tokens
   - Homebrew tokens: GitHub tokens stored in Homebrew configuration

2. CRYPTOCURRENCY WALLET TARGETING:
   - Exodus, Electrum, MetaMask (browser extension), Phantom, Ledger Live desktop app
   - Wallet files, seed phrases, private keys in macOS Keychain or application data
   - Clipboard monitoring for cryptocurrency addresses (address substitution)

3. macOS-SPECIFIC PERSISTENCE:
   - LaunchAgents: ~/Library/LaunchAgents/ — user-level persistence surviving reboot
   - LaunchDaemons: /Library/LaunchDaemons/ (requires elevation) — system-level persistence
   - Login Items: ~/Library/Preferences/ com.apple.loginitems.plist
   - Periodic scripts: /usr/local/etc/periodic/ for scheduled execution
   - VS Code extension auto-update: malicious extension persists through IDE restarts
   - Gatekeeper bypass: unsigned code loaded as VS Code extension subprocess avoids Gatekeeper checks because VS Code itself is signed/notarized

4. DATA EXFILTRATION:
   - Source code repositories: git clone of all local repos to attacker C2
   - Environment variables: contains API keys, database URLs, secrets
   - .env files: development secrets in project directories
   - Docker configurations: docker-compose.yml with database credentials
   - Kubernetes configs: ~/.kube/config with cluster access tokens

GATEKEEPER BYPASS MECHANISM:

macOS Gatekeeper validates that applications are signed and notarized by Apple. VS Code itself passes Gatekeeper validation (signed by Microsoft). Extensions loaded BY VS Code execute as child processes of the signed VS Code application — Gatekeeper does not independently validate extension code. This means:
- GlassWorm code runs with full user privileges
- macOS does not prompt the user about unsigned code
- XProtect malware scanning may not inspect VS Code extension directories
- The extension inherits VS Code's TCC (Transparency, Consent, and Control) permissions
- If the developer granted VS Code Full Disk Access, GlassWorm inherits it

IMPACT CHAIN:

Single compromised developer workstation → SSH keys → GitHub org access → production deployment keys → cloud infrastructure → customer data. The developer's machine is the nexus of maximum credential concentration.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1553 Subvert Trust Controls
- T1027 Obfuscated Files or Information
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1056 Input Capture
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1082 System Information Discovery
- T1518 Software Discovery
- T1584 Compromise Infrastructure
- T1199 Trusted Relationship
- T1204 User Execution
- T1546 Event Triggered Execution
- T1218 System Binary Proxy Execution
- T1685 Disable or Modify Tools
- T1539 Steal Web Session Cookie
- T1115 Clipboard Data
- T1530 Data from Cloud Storage
- T1021 Remote Services
- T1550 Use Alternate Authentication Material
- T1608 Stage Capabilities
- T1588 Obtain Capabilities
- T1591 Gather Victim Org Information

## Sources

- [Aqua Nautilus — VS Code Extension Marketplace Security Research](https://www.aquasec.com/blog/can-you-trust-your-vscode-extensions/)
- [OpenVSX Registry](https://open-vsx.org/)
- [Microsoft — VS Code Marketplace Trust Model](https://code.visualstudio.com/docs/editor/extension-marketplace)
- [Apple — macOS Gatekeeper and Notarization](https://developer.apple.com/documentation/security/notarizing_macos_software_before_distribution)
- [MITRE ATT&CK — Supply Chain Compromise (T1195)](https://attack.mitre.org/techniques/T1195/)
- [MITRE ATT&CK — Masquerading (T1036.005)](https://attack.mitre.org/techniques/T1036/005/)
- [Snyk — VS Code Extension Security](https://snyk.io/blog/visual-studio-code-extension-security-vulnerabilities-deep-dive/)
- [Objective-See — macOS Malware Analysis](https://objective-see.org/blog.html)
- [Patrick Wardle — Art of Mac Malware](https://taomm.org/)
- [StackOverflow — IDE Market Share Survey](https://survey.stackoverflow.co/2022/)
- [CISA — Software Supply Chain Security](https://www.cisa.gov/software-supply-chain-security)
- [VSCodium — VS Code without Microsoft telemetry (uses OpenVSX)](https://github.com/VSCodium/vscodium)
- [Phylum — IDE Extension Supply Chain Analysis](https://blog.phylum.io/)
- [CheckmarxSAST — VS Code Extension Attacks](https://checkmarx.com/blog/)
- [Eclipse Foundation — OpenVSX Terms](https://www.eclipse.org/legal/open-vsx-registry-terms/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0034
