Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
Cybersecurity researchers have released details of a supply chain attack targeting the Open VSX Registry in which anonymous threat actors hijacked a legal developer's resources to distribute malicious updates to downstream users.
According to a Saturday report by Socket security researcher Kirill Boychenko, on January 30, 2026, four well-known Open VSX extensions supplied by the oorzc creator had malicious versions submitted to Open VSX that incorporate the GlassWorm malware loader.
These extensions had previously been advertised as legitimate development utilities (some first published more than two years ago) and combined garnered over 22,000 Open VSX downloads prior to the malicious releases.
The Open VSX security team evaluated the incident as including the use of either a le...

