Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

Prediction markets are ditching the 'casino' label to become a regular part of how people track the news

May 2, 2026

Altura Enables On-chain Lending With AVLT on Morpho

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Hacker target the OpenVSX ecosystem to steal crypto wallets
Security

Hacker target the OpenVSX ecosystem to steal crypto wallets

April 30, 2026No Comments4 Mins Read

GlassWorm, a known malware, has put 73 harmful extensions into OpenVSX’s registry. Hackers use it to steal developers’ crypto wallets and other data.

Security researchers found that six extensions have already turned into active payloads. The extensions were uploaded as fake copies of well-known listings that weren’t harmful. According to a report from Socket, the bad code comes in a later update.

GlassWorm malware attacks crypto devs

In October 2025, GlassWorm first appeared. It used invisible Unicode characters to hide code intended to steal crypto wallet data and developer credentials. The campaign has since spread to npm packages, GitHub repositories, the Visual Studio Code Marketplace, and OpenVSX.

A wave hit hundreds of repositories and dozens of extensions in the middle of March 2026, but its size caught people’s attention. Several research groups noticed the activity early on and helped stop it.

The attackers appear to have changed their approach. The latest batch doesn’t embed malware right away; instead, it uses a delayed activation model. It sends a clean extension, builds an install base, and then sends a bad update.

“Cloned or impersonating extensions are first published without an obvious payload, then later updated to deliver malware,” Socket researchers said.

Security researchers found three ways to deliver the malicious code across the 73 extensions. One way is to use a second VSIX package from GitHub while the program is running and install it using CLI commands. Another method loads platform-specific compiled modules like [.]node files that contain the core logic, including routines for getting more payloads.

See also  $11.4B Lost to Crypto Scams in 2025: FBI Internet Crime Report

A third way uses heavily obfuscated JavaScript that decodes at runtime to download and install malicious extensions. It also has encrypted or fallback URLs for getting the payload.

The extensions look a lot like genuine listings.

In one case, the attacker copied the icon of the genuine extension and gave it a name and description that were almost the same. The publisher name and the unique identifier are what set them apart, but most developers don’t look closely at these things before installing.

GlassWorm is built to go after access tokens, crypto wallet data, SSH keys, and information about the developer environment.

Crypto wallets are continuously under attack from hackers

The threat goes beyond just crypto wallets. A different but related incident shows how supply chain attacks can spread through devs infrastructure.

On April 22, the npm registry hosted a bad version of Bitwarden’s CLI for 93 minutes under the official package name @bitwarden/[email protected]. JFrog, a security company, found that the payload stole GitHub tokens, npm tokens, SSH keys, AWS and Azure credentials, and GitHub Actions secrets.

JFrog’s analysis found that the hacked package modified the install hook and binary entrypoint to load the Bun runtime and run an obfuscated payload, both during installation and while running.

According to the company’s own records, Bitwarden has more than 50,000 businesses and 10 million users. Socket linked that attack to a bigger campaign tracked by Checkmarx researchers, and Bitwarden confirmed the connection.

The problem relies on how npm and other registries operate. Attackers exploit the time between when a package is published and when its contents are checked.

See also  Project 0 reports user losses from domain hijack amid escalating Ethereum losses

Sonatype found about 454,600 new malicious packages infesting registries in 2025. Threat actors looking to gain access to crypto custody, DeFi, and token launchpads have begun targeting registries and releasing malicious workflows.

For developers who installed any of the 73 flagged OpenVSX extensions, Socket recommends rotating all secrets and cleaning their development environments.

The next thing to watch is whether the remaining 67 dormant extensions activate in the coming days, and whether OpenVSX implements additional review controls for extension updates.

Source link

Crypto Ecosystem Hacker OpenVSX Steal Target wallets

Related Posts

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

El Salvador Crypto Remittances Reach $17.38M

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Kalshi and Polymarket face a “sports gambling” probe that could void your trades and shut down the market

February 4, 2026

Solana Co-Founder Pushes Court-led Freeze on Stablecoins

April 14, 2026

NFT Marketplace OpenSea Cuts Staff

November 3, 2023

Type above and press Enter to search. Press Esc to cancel.