#glassworm

[ follow ]
fromInfoWorld
1 day ago

How GlassWorm wormed its way back into developers' code - and what it says about open source security

Just a little over two weeks after GlassWorm was declared "fully contained and closed" by the open source OpenVSX project, the self-propagating worm is once again targeting Visual Studio Code extensions, add-ons that enhance open source VS Code, providing new features, debuggers, and other tools to improve developer workflows. Researchers from Koi have discovered a new wave of infections and three more compromised extensions.
Information security
#vs-code-extensions
Information security
fromTechzine Global
5 days ago

Invisible malware spread via VS Code extensions

GlassWorm infected Visual Studio Code extensions using invisible Unicode and Solana blockchain command-and-control; OpenVSX was impacted but later contained and remediated.
[ Load more ]