Mark RadarMARK RADAR
EN

GlassWorm Targets Open VSX Marketplace, Uses Solana Blockchain to Conceal Operations

5 reports · First detected 2026-03-16 · Last active 2026-05-28

GlassWorm has targeted the VS Code and Open VSX developer ecosystems since October 2025, using stolen publishing tokens to compromise packages and repositories. It uses Solana transaction memos as a command-and-control, or C2, “dead drop,” allowing it to change server locations dynamically. That makes conventional domain blocking and static scanning less effective and heightens the software supply-chain risk.

Socket disclosed on March 13, 2026, that attackers had added at least 72 malicious Open VSX packages since January 31, exploiting extensionPack and extensionDependencies to pass dependencies along and evade review. On May 26, CrowdStrike, Google and Shadowserver disrupted four types of C2 channels. Two more GlassWASM packages were discovered on June 16 and removed after they were reported.

All Coverage

5 original reports

The Backstory

The history behind this event
GlassWorm Spreads to Chrome Extensions, Targets Crypto Wallet Assets2026-03-19 · 1 reports · similarity 0.81

GlassWorm is a supply-chain worm targeting the developer community, planting malicious code in infected software and continuing to spread. The attack has now extended to Chrome extensions, potentially putting browser credentials and the crypto assets of Ledger and Trezor hardware wallet users at risk.

Cybersecurity firm Aikido warned that GlassWorm has used compromised Chrome extensions to install remote access trojans, or RATs, allowing it to circumvent encryption protections and take control of victims’ devices. As of July 20, 2026, reports had not disclosed the number of affected extensions or victims, the exact amount lost, or when the attacks began.

Mark Radar|MARK RADAR