GlassWorm plants sleeper extensions in the Open VSX marketplace
Socket has documented a new wave of the GlassWorm campaign, this time aimed at developer environments through 73 sleeper extensions in the Open VSX marketplace. The extensions are benign at install time and build trust before being weaponised through a later update. Several have already been activated to deliver malicious payloads, while the rest sit dormant in developer environments.
What this means for your organisation
The campaign exploits the fact that software approval usually happens once, at installation. An extension that was clean when it was assessed can change behaviour weeks or months later with no visible warning. A developer machine typically has access to source code, production keys and internal environments, which makes it an effective launch point for further intrusion. For the organisation this is a question of how the developer toolchain is governed, not merely what was installed.
Berigo recommends
- Build an inventory of which extensions are actually installed across developer environments, and keep it current.
- Disable automatic extension updates and pin to specific versions where possible.
- Consider controlling extension installation through an approved internal list rather than open access to the marketplace.
- Make sure developer machines log outbound network traffic, so the activation of a dormant extension can be spotted.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch