📈 Get daily crypto insights that make you smarter about your money

GlassWorm: Invisible Malware Worm Targets VS Code Extensions and Crypto Wallets

A sophisticated new threat dubbed GlassWorm has emerged as the first self-propagating worm to target developer extensions on the OpenVSX marketplace, employing invisible Unicode characters to hide malicious code from human reviewers. With Bitcoin trading around $108,666 and the broader crypto market capitalization exceeding $3.4 trillion, the attack targets 49 different cryptocurrency wallet extensions in a campaign that security researchers describe as one of the most advanced supply chain compromises ever documented.

The Exploit Mechanics

GlassWorm represents a fundamental evolution in supply chain attack methodology. The worm uses Unicode variation selectors — special characters that are part of the Unicode specification but produce no visual output — to embed malicious code that is literally invisible in code editors. When researchers at Koi examined the infected CodeJoy extension (version 1.8.3), they discovered massive gaps between lines of code that appeared to be empty space but actually contained fully functional malware encoded in unprintable characters.

The attack chain begins with the initial infection of a legitimate extension. Once installed, GlassWorm harvests NPM, GitHub, and Git credentials from the developer’s machine. These stolen credentials are then used to compromise additional packages and extensions, creating a self-propagating cycle that spreads the worm further across the developer ecosystem.

Beyond credential theft, GlassWorm deploys SOCKS proxy servers that turn infected developer machines into criminal infrastructure nodes. Hidden VNC servers provide attackers with complete remote access to compromised systems. The malware also specifically targets cryptocurrency wallet extensions — 49 different wallet add-ons are in its crosshairs — draining funds from unsuspecting users who installed what appeared to be legitimate productivity tools.

Affected Systems

The initial wave was detected on October 17, 2025, when seven OpenVSX extensions were found compromised with a combined total of approximately 35,800 downloads. By October 19, a new infected extension was discovered on Microsoft’s official VSCode marketplace, still actively distributing malware. At the time of reporting, ten extensions were still actively distributing the malware across both OpenVSX and VSCode marketplaces.

The attacker’s command-and-control infrastructure uses blockchain-based hosting, making it resistant to traditional takedown methods. The C2 servers communicate through Ethereum and BNB Smart Chain smart contracts, using eth_call queries that incur zero gas fees and leave no transaction records. Google Calendar serves as a backup command server, creating a resilient multi-layered communication architecture.

The Mitigation Strategy

Organizations should immediately audit all installed VSCode and OpenVSX extensions against known compromised package lists. Developers should enable Constrained Language Mode in PowerShell environments and implement network monitoring for outbound JSON-RPC queries to public blockchain nodes, which may indicate C2 communication.

For crypto wallet users specifically, the attack underscores the critical importance of hardware wallet usage for significant holdings. Browser-based wallet extensions, while convenient, remain vulnerable to supply chain attacks through the development tools ecosystem. Segmenting crypto wallet access to hardened workstations isolated from development environments provides an additional layer of protection.

Lessons Learned

GlassWorm demonstrates that traditional code review processes are insufficient when attackers can render malicious payloads invisible to human reviewers. The combination of Unicode stealth techniques with blockchain-based C2 infrastructure creates a threat that is both difficult to detect and nearly impossible to take down through conventional means. The crypto community must adopt automated code analysis tools that can detect anomalous Unicode sequences and behavioral analysis that flags unexpected credential access patterns.

User Action Required

If you have installed any VSCode or OpenVSX extensions in the past two weeks, immediately check the extension publisher and version history against the known compromised list. Rotate any credentials that may have been exposed, particularly GitHub tokens, NPM tokens, and any crypto wallet private keys that were accessible on the same machine. Enable two-factor authentication on all developer accounts and consider migrating significant crypto holdings to hardware wallets until the full scope of the compromise is understood.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified professionals for security decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “GlassWorm: Invisible Malware Worm Targets VS Code Extensions and Crypto Wallets”

  1. 450MB of null bytes in CodeJoy 1.8.3 and nobody noticed for weeks. VS Code extension reviews are basically honor system. OpenVSX has less scrutiny than a Chrome Web Store plugin

  2. 49 wallet extensions targeted with invisible unicode malware. if you have metamask installed you should literally check your extension list right now

  3. invisible unicode characters hiding malware in code reviews is genuinely terrifying. every package manager and extension store needs variation selector scanning now

  4. CodeJoy 1.8.3 had 450MB of null bytes and invisible unicode malware. the review process is literally just hope nobody complains

  5. 49 crypto wallet extensions targeted by invisible Unicode characters. the fact that CodeJoy 1.8.3 passed review means every extension marketplace needs automated Unicode anomaly detection yesterday

    1. unicode_ghost_ 450MB of null bytes to evade AV was found in CodeJoy but the unicode trick is the real innovation. you literally cannot see the malware while staring at the source code

  6. unicode variation selectors producing zero visual output in the editor is genuinely clever. malware you can stare at and not see. every package manager needs variation selector scanning now

    1. code_audit_rat

      invisible_code_ unicode variation selectors are used legitimately in internationalization. banning them globally breaks CJK rendering. the fix is scoped scanning not blanket rejection

  7. unicode variation selectors to hide malware is next level. reviewers literally cannot see the malicious code even staring right at it. the vscode extension ecosystem is a ticking time bomb

    1. ext_dev_ the unicode variation selector trick is invisible to humans but trivially detectable with a regex scan. the fact that no marketplace does this automatically is embarrassing

      1. unicode_hunter_

        unicode_audit_ a regex scan for variation selectors is 5 lines of code. the fact that no marketplace runs it automatically tells you everything about extension security

    2. unicode_nightmare

      ext_dev_ the real issue is OpenVSX has no automated Unicode anomaly detection. VS Code marketplace at least runs some static analysis but even that would miss variation selectors

    3. 49 wallet extensions targeted in one campaign. if you have metamask or phantom installed check your extension list right now

      1. 49 wallet extensions targeted and security researchers only found this after CodeJoy 1.8.3 was already live. the review process is reactive not proactive

      2. the $3.4T crypto market cap makes every extension a target. MetaMask alone has millions of installs. one compromised update and the drain happens in minutes before anyone notices

        1. audit_fortress_

          Devansh R. the 3.4T crypto market cap means every wallet extension is a multi billion dollar target. openVSX review process isn’t built for this threat level

  8. supply_chain_z

    CodeJoy 1.8.3 had invisible malware between lines. how many other extensions are compromised that nobody has found yet

    1. supply_chain_z codejoy 1.8.3 had malware you literally could not see in the editor. the review process for extensions is completely broken

      1. Praful N. reactive not proactive is exactly right. security researchers found GlassWorm AFTER it was live. the review process is an honor system

    2. Kwame B. 49 wallet extensions in one campaign. if you installed anything from OpenVSX in october 2025 check your extension list and your wallets

  9. 49 wallet extensions targeted and the researcher found it AFTER it was live. every VS Code user running crypto extensions should audit their profile today

    1. Mira Patel hard agree. i switched to a separate browser profile for anything touching wallets after the last supply chain scare. convenience got people rekt

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,804.00-0.2%ETH$1,918.53+0.0%SOL$76.35+2.0%BNB$601.74+1.2%XRP$1.04-0.1%ADA$0.1961-1.4%DOGE$0.0701-0.4%DOT$0.8063-1.2%AVAX$6.48-1.0%LINK$8.30+0.2%UNI$4.01+0.4%ATOM$1.38-0.4%LTC$46.19+1.4%ARB$0.0774-1.9%NEAR$1.62+1.1%FIL$0.7114-0.3%SUI$0.6922-0.2%BTC$64,804.00-0.2%ETH$1,918.53+0.0%SOL$76.35+2.0%BNB$601.74+1.2%XRP$1.04-0.1%ADA$0.1961-1.4%DOGE$0.0701-0.4%DOT$0.8063-1.2%AVAX$6.48-1.0%LINK$8.30+0.2%UNI$4.01+0.4%ATOM$1.38-0.4%LTC$46.19+1.4%ARB$0.0774-1.9%NEAR$1.62+1.1%FIL$0.7114-0.3%SUI$0.6922-0.2%
Scroll to Top