‹ Back to Home

GlassWorm Malware Hits 400+ Code Repos on GitHub, npm, VSCode, and OpenVSX

GlassWorm malware has compromised 400+ repositories across GitHub, npm, VSCode Marketplace, and OpenVSX — one of the most widespread supply chain attacks targeting developers in recent history. Here is what it does, how to check if you are affected, and how to stay safe.

Keerthika 6 min read 525
Follow on Google
Updated 2 weeks ago
Security GlassWorm Malware Hits 400+ Code Repos on GitHub, npm, VSCode, and OpenVSX 6 min left Follow on Google
GlassWorm Malware Hits 400+ Code Repos on GitHub, npm, VSCode, and OpenVSX

TamilTech AI summary

GlassWorm is a stealthy supply-chain malware that slipped into over 400 code repositories and packages across GitHub, npm, the VSCode Marketplace, and OpenVSX, so anyone who installs packages, extensions, or clones public repos should take this seriously. It spreads through typosquatting, dependency confusion, stolen maintainer accounts, and lookalike extensions, then fingerprints machines, harvests credentials like SSH keys, AWS secrets, and API tokens, phones home over HTTPS, and tries to stick around via Git hooks and CI/CD. Detection is tough because the payload is obfuscated, often stays dormant, and only activates in certain environments while blending in with normal traffic. GitHub, npm, Microsoft, and OpenVSX have pulled bad packages and accounts and tightened scanning and publisher checks, but you should still audit dependencies with npm audit, review extensions carefully, rotate exposed credentials, enable 2FA, pin versions, and avoid committing secrets. Treat every package and extension as a potential risk, because attacks on developer tools are rising and a single bad install can put your machine and your clients’ systems at risk.

  • What is GlassWorm malware?
  • How do I know if I installed a GlassWorm-infected package?
  • What should I do if I may have been affected?
  • Is my VSCode safe to use?

AI-assisted summary, checked by the TamilTech editorial team.

GlassWorm Malware Hits 400+ Code Repositories on GitHub, npm, VSCode, and OpenVSX

A sophisticated new malware campaign has sent shockwaves through the global developer community. Security researchers have discovered GlassWorm — a stealthy, multi-platform malware strain that has successfully infiltrated over 400 code repositories across GitHub, the npm package registry, VSCode Marketplace, and OpenVSX. The attack represents one of the most widespread software supply chain compromises targeting developers in recent memory.

If you are a developer who installs npm packages, VSCode extensions, or clones public GitHub repositories, this threat is directly relevant to you.

What Is GlassWorm?

GlassWorm is a supply chain malware — a type of attack that embeds malicious code inside legitimate-looking software packages, extensions, or repositories that developers trust and use daily. Unlike traditional malware that targets end users, supply chain attacks target developers themselves, exploiting the trust developers place in the open-source ecosystem.

Premium Content

You've read all your free articles today. Subscribe to continue reading.

You've used 3 of 3 free articles today.

Subscribe Now

Already subscribed? Sign in

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,346 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications