<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b" -->

---
title: Protect Yourself from the Glassworm Attacking VSCode...
description: GlassWorm is a self-propagating worm targeting VS Code extension marketplaces, having infected 14 extensions with 35,800+ downloads. The malware uses invisible...
canonical: https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Protect Yourself from the Glassworm Attacking VSCode Extensions | daily.dev
og:description: GlassWorm is a self-propagating worm targeting VS Code extension marketplaces, having infected 14 extensions with 35,800+ downloads. The malware uses invisible...
og:url: https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b
og:image: https://api.daily.dev/og/posts/EaB8ln89B.png
og:image:alt: Protect Yourself from the Glassworm Attacking VSCode Extensions
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Protect Yourself from the Glassworm Attacking VSCode Extensions

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

GlassWorm is a self-propagating worm targeting VS Code extension marketplaces, having infected 14 extensions with 35,800+ downloads. The malware uses invisible Unicode characters to hide malicious code, steals credentials from NPM, GitHub, and Git, drains cryptocurrency wallets, and provides remote access via SOCKS proxies and VNC servers. It leverages Solana blockchain for command-and-control and auto-updates to spread. Developers should audit extensions using tools like vscan.dev, disable auto-updates, block untrusted sources, rotate credentials immediately, and strengthen supply chain security protocols.

## Content

# GlassWorm: An Immediate Threat to Developers Using VS Code Extensions

A new sophisticated self-propagating worm, named GlassWorm, is currently targeting Visual Studio Code extension marketplaces, including OpenVSX and Microsoft Extension Marketplace. Having infected 14 extensions with approximately 35,800 downloads, GlassWorm poses a significant risk to developer environments.

## How GlassWorm Operates

GlassWorm utilizes invisible Unicode characters to insert malicious code, allowing it to evade detection during standard code reviews. Once the extension containing the worm is installed, it acts as a Remote Access Trojan (RAT). This malware steals credentials from NPM, GitHub, and Git, drains cryptocurrency wallets, and provides unauthorized remote access through SOCKS proxies and hidden VNC servers.

The worm's spread is facilitated by the Solana blockchain for its command-and-control infrastructure, using Google Calendar as a fallback method. Infected extensions are capable of auto-updating themselves, thus propagating the worm without user intervention.

## Recommended Security Measures

Given the scale and sophistication of this security threat, developers are advised to take immediate actions:

1. **Audit and Scan**: Use security tools like vscan.dev to audit all installed VS Code extensions. Regularly scan for suspicious behaviors, risky API usage, and potentially vulnerable dependencies.

2. **Disable Auto-Updates**: Temporarily disable auto-updates on extensions to prevent the worm from spreading through automated updates.

3. **Block Untrusted Sources**: Block extensions from untrusted marketplaces and refrain from installing extensions from unknown sources.

4. **Rotate Credentials**: Immediately rotate all passwords and tokens associated with NPM, GitHub, and Git to prevent unauthorized access.

5. **Strengthen Security Protocols**: Implement stricter supply chain security measures to protect against similar threats in the future.

## Conclusion

GlassWorm represents the second major supply chain attack on developers in recent months, highlighting the imperative need for rigorous security protocols. By taking these proactive steps, developers can protect their environments from this self-propagating threat and safeguard their credentials and data.

---

Tags: [#security](https://daily.dev/tags/security), [#devops](https://daily.dev/tags/devops), [#malware](https://daily.dev/tags/malware), [#vscode](https://daily.dev/tags/vscode), [#supply-chain](https://daily.dev/tags/supply-chain)

[View this post on daily.dev](https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Protect Yourself from the Glassworm Attacking VSCode Extensions","url":"https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b"},"datePublished":"2025-10-22T01:43:06.622Z","dateModified":"2025-10-24T07:47:09.522Z","description":"GlassWorm is a self-propagating worm targeting VS Code extension marketplaces, having infected 14 extensions with 35,800+ downloads. The malware uses invisible...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7b81e22a2905db8a0227bd45ff6534cd?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7b81e22a2905db8a0227bd45ff6534cd?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/protect-yourself-from-the-glassworm-attacking-vscode-extensions-eab8ln89b","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,devops,malware,vscode,supply-chain","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Protect Yourself from the Glassworm Attacking VSCode Extensions"}]}
```

