Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Open VSX extensions hijacked: GlassWorm malware spreads by way of dependency abuse

    March 17, 2026

    AI Toys Can Pose Security Issues for Kids, New Research Suggests Warning

    March 17, 2026

    AWS and NVIDIA deepen strategic collaboration to speed up AI from pilot to manufacturing

    March 17, 2026
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Open VSX extensions hijacked: GlassWorm malware spreads by way of dependency abuse
    AI Ethics & Regulation

    Open VSX extensions hijacked: GlassWorm malware spreads by way of dependency abuse

    Declan MurphyBy Declan MurphyMarch 17, 2026No Comments1 Min Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Open VSX extensions hijacked: GlassWorm malware spreads by way of dependency abuse
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link



    The most recent wave additionally mimics extensively used developer instruments to maximise set up possibilities. “The extensions overwhelmingly impersonate extensively put in developer utilities: linters and formatters like ESLint and Prettier, code runners, standard language tooling for Angular, Flutter, Python, and Vue, and customary quality-of-life extensions like vscode-icons, WakaTime, and Higher Feedback,” the researchers mentioned. “Notably, the marketing campaign additionally targets AI developer tooling, with extensions focusing on Claude Code, Codex, and Antigravity.”

    The researchers added that as of March 13, Open VSX has eliminated the vast majority of the transitively malicious extensions, but a number of stay reside, indicating ongoing takedowns.

    Socket printed indicators of compromise (IOCs) tied to the marketing campaign, together with the names of dozens of malicious Open VSX extensions and related writer accounts believed to be linked to the operation. Moreover, the researchers suggest treating extension dependencies with the identical scrutiny sometimes utilized to software program packages. Organizations ought to monitor extension updates, audit dependency relationships, and limit set up to trusted publishers the place potential, as attackers more and more exploit the developer tooling ecosystem as a supply-chain entry level.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Justin Fulcher on AI’s Position in Modernizing Authorities Operations

    March 16, 2026

    AI-Assisted Phishing Marketing campaign Harvesting Sufferer Information

    March 16, 2026

    Gaming Clans Develop into Progress Engine for Playnance Ecosystem

    March 16, 2026
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    Open VSX extensions hijacked: GlassWorm malware spreads by way of dependency abuse

    By Declan MurphyMarch 17, 2026

    The most recent wave additionally mimics extensively used developer instruments to maximise set up possibilities.…

    AI Toys Can Pose Security Issues for Kids, New Research Suggests Warning

    March 17, 2026

    AWS and NVIDIA deepen strategic collaboration to speed up AI from pilot to manufacturing

    March 17, 2026

    7 Steps in direction of making AI a differentiator in your corporation

    March 17, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2026 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.