The GlassWorm VS Code Extension Worm
Updated 5 Oct 2026 · Incident date 17 Oct 2025 · IDE extension
codejoy.codejoy-vscode-extension 1.8.2 -> 1.8.3/1.8.4, plus JScearcy.rust-doc-viewer 4.2.1, CodeInKlingon.git-worktree-menu 1.0.9, srcery-colors.srcery-colors 0.3.9, sissel.shopify-liquid 4.0.1 and ~10 morebundled extension JavaScript with the payload hidden in Unicode variation selectorsGlassWorm was a self-spreading supply chain attack on VS Code extensions. In October 2025 attackers pushed bad versions of clean extensions on Open VSX, for example codejoy.codejoy-vscode-extension 1.8.3 and 1.8.4. The bad code hid inside invisible Unicode characters.
The extensions stole developer credentials and gave the attackers remote access. The stolen npm and GitHub credentials let the malware spread to more extensions.
What happened
On 17 October 2025, seven Open VSX extensions received poisoned updates, with about 35,800 downloads in total, according to Truesec. On 19 October a new infected extension appeared on the Microsoft VS Code marketplace.
The malicious code used invisible Unicode and Private Use Area characters. These characters do not show in a code editor, so a reviewer who reads the source sees nothing. Veracode describes the technique and the two command channels.
The malware looked for payload addresses in a Solana blockchain transaction. A Google Calendar event served as a backup channel. Both use normal public services, which makes the traffic hard to block.
The malware then did several things on the developer machine:
- It collected npm, GitHub and Git credentials.
- It targeted 49 cryptocurrency wallet extensions.
- It started a SOCKS proxy, so the machine could carry criminal traffic.
- It installed a hidden VNC server for full remote access.
This is why it is called a worm. The stolen credentials let the malware publish poisoned versions of other packages and extensions that the victim could update. Veracode names npm tokens, GitHub credentials and Open VSX access tokens as the stolen items.
Affected versions
Truesec lists these extension versions as compromised. Each one was a clean extension before the update.
- Open VSX:
codejoy.codejoy-vscode-extension1.8.3 and 1.8.4 l-igh-t.vscode-theme-seti-folder1.2.3kleinesfilmroellchen.serenity-dsl-syntaxhighlight0.3.2JScearcy.rust-doc-viewer4.2.1SIRILMP.dark-theme-sm3.11.4CodeInKlingon.git-worktree-menu1.0.9 and 1.0.91ginfuru.better-nunjucks0.3.2ellacrity.recoil0.7.4grrrck.positron-plus-1-e0.0.71jeronimoekerdt.color-picker-universal2.8.91srcery-colors.srcery-colors0.3.9sissel.shopify-liquid4.0.1TretinV3.forts-api-extention0.3.1- VS Code Marketplace:
cline-ai-main.cline-ai-agent3.1.3
The worm kept spreading after the first report, so this list is not final. Check any extension you installed or updated in October 2025.
Indicators of compromise
Truesec publishes these indicators. Search your proxy, DNS and endpoint logs for them.
- Primary command server IP:
217.69.3.218 - Exfiltration endpoint:
140.82.52.31:80/wall - Payload paths on the command server:
/get_arhive_npm/and/get_zombi_payload/ - Solana wallet used as a command channel:
28PKnu7RzizxBzFPoLp69HLXp9bJL3JFtT2s5QzHsEA2 - Backup channel: a Google Calendar event at
calendar.app.google/M2ZCvM8ULL56PD1d6, organizeruhjdclolkdn@gmail.com - Persistence: new entries under
HKCU\Software\Microsoft\Windows\CurrentVersion\RunandHKLM\Software\Microsoft\Windows\CurrentVersion\Run
How to check
List your installed extensions and versions, then compare them with the affected list above.
code --list-extensions --show-versions
The extension folders also hold the files. This command searches them for the primary command server address.
grep -rl "217.69.3.218" ~/.vscode/extensions ~/.vscode-oss/extensions 2>/dev/null
On Windows, also look at the two Run registry keys above for entries you did not create. Check network logs for connections to the listed IP addresses.
What to do now
- Remove any affected extension version and restart the editor.
- Treat the machine as compromised if one was installed. The malware installs remote access.
- Rotate npm tokens, GitHub tokens, Git credentials and Open VSX tokens from a clean machine.
- Check your wallets for unauthorized activity if you use wallet extensions.
- Review the packages and extensions you publish for versions you did not release.
- Keep an inventory of installed extensions, install only from verified publishers, and consider turning off auto-update so you can review changes.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks for other supply chain cases.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 80 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED extension.js It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
What is GlassWorm?
GlassWorm is a self-spreading attack on VS Code extensions found in October 2025. It hid code in invisible Unicode characters, stole credentials and used them to infect more extensions.
How do I know if I installed a GlassWorm extension?
Run code --list-extensions --show-versions and compare the result with the compromised extension versions published by Truesec. Also search your logs for the command server IP 217.69.3.218.
Sources
More supply chain attacks
- Nx Console VS Code extension 18.95.0 compromise (TeamPCP / GitHub breach) 18 May 2026
- Amazon Q Developer for VS Code malicious commit 17 Jul 2025
- ETHcode VS Code extension malicious pull request 17 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.