Drooid Logo
Back to today’s briefing

Story perspectives

Supply Chain Attack Revives GlassWorm, Targets Developers

2/2/2026

25 6 Full Breakdown

1 of 1

Story summary
  • The Open VSX marketplace faced a supply chain attack enabling GlassWorm to reappear.
  • On January 30, a threat actor compromised a publisher's account and released malicious versions of four VS Code extensions with 22,000 downloads.
  • The extensions targeted macOS and stole cookies and developer credentials, using encrypted loaders for execution.
  • Separately, Hugging Face's infrastructure delivered TrustBastion, an Android remote access trojan masquerading as a security app to gain permissions.