GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住关键点。 文章讲的是GlassWorm供应链攻击卷土重来,这次攻击针对GitHub、npm和VSCode/OpenVSX上的数百个包、仓库和扩展。研究人员发现了433个被黑的组件。攻击者使用相同的Solana区块链地址、相似的载荷和共享基础设施,表明是同一个威胁行为者所为。 GlassWorm最早在去年十月出现,利用Unicode字符隐藏恶意代码,窃取加密货币钱包数据和开发者凭证。这次攻击范围更大,涉及200个GitHub Python仓库、151个JS/TS仓库、72个VSCode扩展和10个npm包。 初始入侵发生在GitHub,通过黑进账户强制推送恶意提交。然后在npm和VSCode上发布恶意包和扩展,使用混淆代码逃避检测。攻击者还利用Solana区块链每五秒查询一次指令,并嵌入到交易中下载Node.js运行时和执行信息窃取器。 恶意软件目标是加密货币钱包数据、凭证、访问令牌、SSH密钥和开发者环境数据。代码注释显示操盘手可能是俄语威胁行为者,但没有足够证据确定归属。 最后,Step Security建议开发者检查特定标记变量“lzcdrtfxyqiplpd”,检查~/init.json文件、Node.js安装情况以及Git提交历史中的异常。 总结的时候要涵盖攻击目标、规模、技术手段以及影响。控制在100字以内,直接描述内容。 </think> GlassWorm供应链攻击再次来袭,针对GitHub、npm及VSCode/OpenVSX上的数百个包与扩展展开大规模入侵。研究人员发现433个被黑组件,攻击者利用相同区块链地址及基础设施跨平台作案。恶意代码隐藏于Unicode字符中,窃取加密货币钱包数据及开发者凭证,并通过GitHub账户强制推送恶意提交扩散。 2026-3-17 21:45:16 Author: www.bleepingcomputer.com(查看原文) 阅读量:2 收藏

GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX

The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions.

Researchers at Aikido, Socket, Step Security, and the OpenSourceMalware community have collectively identified 433 compromised components this month in attacks attributed to GlassWorm.

Evidence of a single threat actor running the GlassWorm campaigns across multiple open-source repositories is provided by the use of the same Solana blockchain address used for command-and-control (C2) activity, identical or functionally similar payloads, and shared infrastructure.

GlassWorm was first observed last October, with attackers using “invisible” Unicode characters to hide malicious code that harvested cryptocurrency wallet data and developer credentials.

The campaign continued with multiple waves and expanded to Microsoft's official Visual Studio Code marketplace and the OpenVSX registry used by unsupported IDEs, as discovered by Secure Annex's researcher, John Tuckner.

macOS systems were also targeted, introducing trojanized clients for Trezor and Ledger, and later targeted developers via compromised OpenVSX extensions.

The latest GlassWorm attack wave is far more extensive, though, and spread to:

  • 200 GitHub Python repositories
  • 151 GitHub JS/TS repositories
  • 72 VSCode/OpenVSX extensions
  • 10 npm packages

Initial compromise occurs on GitHub, where accounts are compromised to force-push malicious commits.

Then, malicious packages and extensions are published on npm and VSCode/OpenVSX, featuring obfuscated code (invisible Unicode characters) to evade detection.

Malicious package on OpenVSX
Malicious package on OpenVSX
Source: Aikido

Across all platforms, the Solana blockchain is queried every five seconds for new instructions. According to Step Security, between November 27, 2025, and March 13, 2026, there were 50 new transactions, mostly to update the payload URL.

The instructions were embedded as memos in the transactions and led to downloading the Node.js runtime and executing a JavaScript-based information stealer. 

GlassWorm attack chain
GlassWorm attack chain
Source: Step Security

The malware targets cryptocurrency wallet data, credentials, and access tokens, SSH keys, and developer environment data.

Analysis of code comments indicates that GlassWorm is orchestrated by Russia-speaking threat actors. Additionally, the malware skips execution if the Russian locale is found on the system. However, this is insufficient data for confident attribution.

Step Security advises developers who install Python packages directly from GitHub or run cloned repositories to check for signs of compromise by searching their codebase for the marker variable “lzcdrtfxyqiplpd,” an indicator of the GlassWorm malware.

Malicious GitHub files
Malicious GitHub files
Source: Step Security

They also recommend inspecting systems for the presence of the ~/init.json file, which is used for persistence, as well as unexpected Node.js installations in the home directory (e.g., ~/node-v22*).

Additionally, developers should look for suspicious i.js files in recently cloned projects and review Git commit histories for anomalies, such as commits where the committer date is significantly newer than the original author date.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/
如有侵权请联系:admin#unsafe.sh