GlassWorm attacks Open VSX through transitive dependencies

Socket describes an evolution of the GlassWorm campaign that abuses the Open VSX extension ecosystem. The malware sits not in the extension itself but in a transitive dependency pulled in indirectly when the extension is installed or updated. The primary package looks legitimate, while the malicious code enters further down the dependency chain.

What this means for your business

Controls that only inspect the package you deliberately chose will not catch this. Approval routines where a developer reads the extension's code and gives a thumbs up create false confidence. The result is compromise at install or update time, without anyone breaching current procedure, and discovery only once credentials are misused somewhere else entirely.

Berigo recommends

  • Require dependency analysis to cover the full tree, not just direct dependencies, and to run on every update.
  • Consider mirroring approved extensions and packages in an internal registry instead of pulling them straight from public sources.
  • Disable automatic extension updates on developer machines and manage versions centrally.
  • Include developer tooling in your vendor inventory. It is third-party software like anything else.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch