s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.glassworm

📛 Threat Title

Malware family: GlassWorm

Category: GlassWorm First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.glassworm`. Printable name: GlassWorm.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.glassworm VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.glassworm

IOC database

Type
domain
Value
js.glassworm
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.glassworm

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.glassworm

References (1)

Remediations (10)

  • web:cybersecsentinel.com

    GlassWorm presents one of the most sophisticated supply-chain threats to date. It leverages legitimate update mechanisms, employs stealth through invisible code, and communicates via decentralised, immutable networks. It compromises developer environments, CI/CD runners, and build pipelines, converting trusted assets into active threat nodes.

  • web:cybersecuritynews.com

    In a major escalation of supply chain attacks, the GlassWorm malware campaign has evolved to infect developer environments using transitive dependencies. On March 13, 2026, the Socket Research Team reported identifying at least 72 new malicious Open VSX extensions linked to this campaign.

  • web:securityarsenal.com

    Defend against the GlassWorm campaign utilizing Solana blockchain dead drops and malicious Chrome extensions. Discover detection strategies and remediation .

  • web:securityboulevard.com

    GlassWorm is evolving. Security researchers say the malware , which infiltrates code repositories with malicious extensions, can now deploy a RAT, is targeting MCP servers, and has a new way of moving through Open VSX.

  • web:socket.dev

    Socket is tracking cloned Open VSX extensions tied to GlassWorm , with several updated from benign-looking sleepers into malware delivery vehicles.

  • web:thehackernews.com

    GlassWorm uses Solana and Google Calendar dead drops to deliver RAT stealing browser data and crypto wallets, impacting developers.

  • web:www.anavem.com

    Glassworm Campaign Plants 73 Malicious VS Code Extensions Researchers discovered 73 malicious Visual Studio Code extensions in OpenVSX that activate after updates to steal sensitive data.

  • web:www.darkreading.com

    The infamous GlassWorm malware has infected dozens more Open VSX software packages, according to new research. GlassWorm is a family of malware that first emerged last year with the goal of ...

  • web:www.koi.ai

    The invisible payload in the new wave of GlassWorm All three extensions contain invisible Unicode malware very similar to what we documented in our original analysis. The malicious code is still literally invisible in code editors - encoded in unprintable Unicode characters that render as blank space to human eyes but execute as JavaScript to the interpreter. The attacker has posted a fresh ...

  • web:www.malwarebytes.com

    GlassWorm hides inside developer tools. Once it's in, it steals data, installs remote access malware , and even a fake browser extension to monitor activity. While it starts with developers, the impact can quickly spread. With stolen credentials, access tokens, and compromised tools, attackers can launch wider supply chain attacks, putting companies and everyday users at risk. How the ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.