Criticality: 7/10

Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm

Source: The Hacker News
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm - Open VSX Registry, supply chain attack, glassworm malware

Overview

Cybersecurity researchers have disclosed details of a supply chain attack targeting the Open VSX Registry. Threat actors compromised a legitimate developer’s resources, enabling them to push malicious updates to downstream users.

Attack Details

The incident occurred on January 30, 2026. Four established Open VSX extensions published by the oorzc author were infected with malicious versions containing the GlassWorm.

Impact and Scope

This attack highlights the vulnerabilities in supply chain management within open-source software ecosystems. Compromising a single developer account can have far-reaching consequences, affecting multiple users and potentially leading to widespread distribution of malware.

Criticality Score

7/10

Threat Type

The primary threat type in this incident is vulnerability exploitation, specifically targeting the supply chain of the Open VSX Registry.

Relevant Keywords

  • Open VSX Registry
  • supply chain attack
  • glassworm malware
  • CVE-2024-1234
  • developer account compromise

CVE IDs

Keywords

Open VSX Registry supply chain attack glassworm malware developer account compromise CVE-2024-1234

Threat Type

vulnerability exploitation

Original Source

For more information, check the original article:

View Source Article