GlassWorm is a credential-stealing, self-propagating malware family targeting software developers through compromised development tools and software supply chains. First identified in October 2025, it has spread through malicious Visual Studio Code extensions distributed on Open VSX and Visual Studio Marketplace, compromised npm and Python packages, and poisoned GitHub repositories. Activity has affected Windows and macOS systems. Its extensions can masquerade as legitimate developer utilities or visual themes, and initially benign extensions can become malicious through updates.
GlassWorm harvests browser credentials, GitHub tokens, npm tokens, Open VSX tokens, and cryptocurrency wallet data. It reuses stolen developer credentials to compromise accounts and inject malicious code into accessible repositories, extending infection to developers who subsequently consume the altered projects. Campaigns have poisoned more than 300 GitHub repositories. GlassWorm also supports persistent access and has used hidden virtual network computing to conduct collection and communication without visible user interaction.
Its execution chains use staged JavaScript payloads, runtime decryption, in-memory execution, and invisible Unicode characters that conceal malicious logic within apparently empty source lines. GlassWorm-associated loaders use Solana transaction memos as dead-drop resolvers for follow-on payload locations, allowing operators to change infrastructure without publishing new extension versions. Some loaders avoid systems with Russian-language or Russian-time-zone settings. A coordinated disruption by CrowdStrike, Google, and the Shadowserver Foundation targeted its command-and-control channels in May 2026, but subsequent GlassWorm-associated activity continued.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These investigations have identified a central figure known online as "ResoluteXBF" with connections to South African-based infrastructure. Even though the group was relatively new when it emerged in 2010, it has rapidly evolved from the Shai-Hulud campaign to subsequent operations that involved malware such as GlassWorm...
A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
« utilisait des noms aléatoires, des échappements hexadécimaux et des caractères Unicode invisibles pour masquer sa charge utile »
« L’extension était publiée sous l’identité microsoft pour se faire passer pour une extension officielle. »
« La blockchain Solana est utilisée comme mécanisme de C2 dynamique, permettant de changer l’infrastructure sans publier de nouvelle version d’extension. »
Its loader uses Solana transaction memos as a dead-drop to dynamically resolve follow-on infrastructure, allowing the threat actor to change the next-stage delivery location without republishing the extension.
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
110 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain worm that compromises developer accounts and repositories to distribute malicious code through projects, packages, and developer extensions. Used as a comparison to illustrate supply-chain risks; the content does not link it to exploitation of the GitLab vulnerability.
Malware distributed through developer-tool extensions, associated with credential theft and persistent access. The investigated theme cluster spans Visual Studio Marketplace and Open VSX. A confirmed GlassWorm-linked loader decrypts embedded JavaScript, avoids Russian-language or Russian-timezone systems, and uses Solana transaction memos to resolve follow-on payload infrastructure. Retrieved JavaScript executes in memory with access to system capabilities. Shared infrastructure, encryption material, and execution patterns support the attribution; development links alone do not establish that every related extension is malicious.
Malware campaign targeting developers through malicious Visual Studio Code theme extensions distributed through Visual Studio Marketplace and Open VSX. The described loaders conceal executable JavaScript using obfuscation, invisible Unicode characters, and AES-256-CBC encryption. They retrieve and execute attacker-controlled payloads, including a Windows command script. One loader avoids systems with Russian language or time-zone settings and obtains subsequent payload addresses from Solana transaction memos, enabling dynamic command-and-control infrastructure changes without extension updates.
Developer-targeting malware distributed through extension ecosystems to steal credentials, session data, cryptocurrency wallets, and developer authentication artifacts. The analyzed loader decrypts embedded JavaScript, avoids Russian-language and Russian-timezone systems, resolves follow-on infrastructure through Solana transaction memos, and executes remotely supplied JavaScript in memory. Matching encryption keys, blockchain infrastructure, and execution behavior connect Cosmic Nebula Themes to GlassWorm with high confidence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.