Cybersecurity researchers have released details of a supply chain attack targeting the Open VSX Registry in which anonymous threat actors hijacked a legal developer’s resources to distribute malicious updates to downstream users.
According to a Saturday report by Socket security researcher Kirill Boychenko, on January 30, 2026, four well-known Open VSX extensions supplied by the oorzc creator had malicious versions submitted to Open VSX that incorporate the GlassWorm malware loader.
These extensions had previously been advertised as legitimate development utilities (some first published more than two years ago) and combined garnered over 22,000 Open VSX downloads prior to the malicious releases.
The Open VSX security team evaluated the incident as including the use of either a leaked token or other unauthorized access read more about Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
