Story perspectives
Supply Chain Attack Revives GlassWorm, Targets Developers
2/2/2026
1 of 1
Story summary
- The Open VSX marketplace faced a supply chain attack enabling GlassWorm to reappear.
- On January 30, a threat actor compromised a publisher's account and released malicious versions of four VS Code extensions with 22,000 downloads.
- The extensions targeted macOS and stole cookies and developer credentials, using encrypted loaders for execution.
- Separately, Hugging Face's infrastructure delivered TrustBastion, an Android remote access trojan masquerading as a security app to gain permissions.
