GlassWorm Malware Hits 400+ Code Repositories on GitHub, npm, VSCode, and OpenVSX
A sophisticated new malware campaign has sent shockwaves through the global developer community. Security researchers have discovered GlassWorm — a stealthy, multi-platform malware strain that has successfully infiltrated over 400 code repositories across GitHub, the npm package registry, VSCode Marketplace, and OpenVSX. The attack represents one of the most widespread software supply chain compromises targeting developers in recent memory.
If you are a developer who installs npm packages, VSCode extensions, or clones public GitHub repositories, this threat is directly relevant to you.
What Is GlassWorm?
GlassWorm is a supply chain malware — a type of attack that embeds malicious code inside legitimate-looking software packages, extensions, or repositories that developers trust and use daily. Unlike traditional malware that targets end users, supply chain attacks target developers themselves, exploiting the trust developers place in the open-source ecosystem.
Premium Content
You've read all your free articles today. Subscribe to continue reading.
You've used 3 of 3 free articles today.
Subscribe NowAlready subscribed? Sign in




Comments (0)
Be the first to comment!