Story perspectives
GlassWorm Malware Targets Visual Studio Code, Steals Credentials
11/10/2025
32 7
1 of 1
Story summary
- GlassWorm malware campaign targets the Visual Studio Code ecosystem with three new malicious extensions that steal GitHub and cryptocurrency credentials.
- The malware hides code with invisible Unicode characters and can self-replicate by compromising extensions.
- Koi Security says the attackers are likely Russian-speaking and used Solana blockchain for command-and-control.
- The campaign has been active for over a month and expanded to GitHub, where stolen credentials are used to push commits.
