GlassWorm v3 Supply Chain Attack — 72 Malicious Open VSX Extensions, 151 GitHub Repos & ZOMBI Botnet Module — Threadlinqs Intelligence
As of 2026-05-30, GlassWorm v3 Supply Chain Attack — 72 Malicious Open VSX Extensions, 151 GitHub Repos & ZOMBI Botnet Module is a high-severity malware threat attributed to PhantomRaven (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0231 · Severity: HIGH · CVSS: 8.6 · Status: DORMANT · Category: MALWARE
Attribution: PhantomRaven · Russia · FINANCIAL
GlassWorm v3 is a self-propagating supply chain worm that compromised 72 Open VSX extensions, injected invisible Unicode-encoded payloads into 151+ GitHub repositories, and deploys the ZOMBI RAT
GlassWorm v3 represents a significant escalation of the GlassWorm supply chain campaign first identified in March 2025. The third wave, active from January through March 2026, abuses Open VSX extensionPack and extensionDependencies fields to create transitive delivery vehicles that pull malicious payloads after trust is established.
The attack chain begins with benign-appearing extensions published to the Open VSX marketplace and VS Code Marketplace. These extensions mimic popular developer utilities including linters, formatters, code runners, and AI-powered coding assistants (impersonating tools like Claude Code and Google Antigravity). Post-publication updates introduce malicious dependencies through extensionPack exploitation and Remote Dynamic Dependencies (RDD) via custom HTTP URLs in package.json.
The obfuscation layer uses Private Use Area (PUA) Unicode characters in the ranges 0xFE00-0xFE0F (variation selectors) and 0xE0100-0xE01EF (supplementary markers) to encode malicious payloads as invisible characters. The injection appears as empty backtick blocks but contains hidden character sequences that decode to full malicious loaders executed via eval(). Surrounding changes are AI-generated and realistic — documentation tweaks, version bumps, small refactors, and bug fixes — making detection extremely difficult.
The C2 infrastructure employs a triple-layer resilience architecture: (1) Solana blockchain transactions serve as dead-drop resolvers — the wallet 28PKnu7RzizxBzFPoLp69HLXp9bJL3JFtT2s5QzHsEA2 stores C2 addresses in transaction memos that cannot be taken down; (2) direct IP connections to 217.69.3.218 and 199.247.10.166 for payload delivery; (3) Google Calendar (calendar.app.google/M2ZCvM8ULL56PD1d6) as a fallback C2 channel.
The final payload is the ZOMBI module — a massive JavaScript RAT that transforms infected developer workstations into criminal infrastructure nodes. ZOMBI capabilities include: credential harvesting (NPM tokens, GitHub tokens, Open VSX credentials, Git credentials, AWS keys, SSH keys), cryptocurrency wallet draining targeting 49 wallet extensions (MetaMask, Coinbase Wallet, Phantom, Electrum, Exodus, Atomic, Ledger, Trezor, Binance, TonKeeper), hidden VNC (HVNC) for invisible remote desktop access, SOCKS proxy for routing traffic through corporate networks, and WebRTC/BitTorrent networking for P2P botnet communication.
The malware performs locale checks to avoid infecting systems with a Russian locale, suggesting Russian-speaking actors. Attribution points to 'PhantomRaven' — an entity that deliberately rotated account names and email addresses to evade tracking. The campaign evolved through four waves: initial Unicode npm attacks (March 2025), first OpenVSX compromise (October 2025), compromised developer account attack (January 2026), and the current mass injection campaign (March 2026).
The GitHub injection campaign (March 3-9, 2026) targeted 151+ repositories including projects with significant star counts (pedronauck/reworm with 1,460 stars). The malware includes a 15-minute execution delay before decrypting and running an AES-256-CBC JavaScript payload, evading sandbox analysis. Persistence mechanisms include Windows Registry Run keys (HKCU and HKLM) and macOS LaunchAgents. Data is staged in /tmp/ijewf/ before exfiltration to 140.82.52.31:80/wall and 199.247.13.106:80/wall.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494, CWE-116
Target sectors: technology, software-development, financial, cryptocurrency, open-source
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1195, T1195, T1059, T1204, T1547, T1543, T1176, T1027, T1027, T1497