New GlassWorm attack targets macOS via compromised OpenVSX extensions

The goal of a recent GlassWorm malware attack using exploited OpenVSX extensions is to steal developer credentials and configurations, crypto-wallet data, and passwords from macOS systems.

After gaining access to the account of a reputable developer (oorzc), the threat actor distributed malicious updates containing the GlassWorm payload to four extensions that had received 22,000 downloads.

The malicious code was concealed by “invisible” Unicode characters in GlassWorm assaults, which initially surfaced in late October and were used to steal developer account information and cryptocurrency wallets. Additionally, SOCKS proxying and VNC-based remote access are supported by the malware.

GlassWorm affected Microsoft’s official Visual Studio Code marketplace as well as OpenVSX read more about New GlassWorm attack targets macOS via compromised OpenVSX extensions.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *