Tuesday, February 3, 2026

Open supply chain hack of VS Code extensions

Be warned the following VS Code extensions are again subject to a supply chain hack, these extensions are reported to have  GlassWorm malware. Extensions named are VSCode Mindmap, FTP/SSH Sync Toy, I18n Tools and Scss to CS.

New GlassWorm attack targets macOS via compromised OpenVSX extensions (bleepingcomputer.com)

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm (thehackernews.com)





No comments:

Post a Comment