Hello friend! I'm sure you know this already but if you're a developer that codes with Visual Studio Code please be aware of this. There is a malware known as "Glassworm" that is resurging for the third wave of malicious VS Code extensions.
It's frightening and when I read the news on BleepingComputer I was shocked to see just how many developers' systems are getting compromised. Your probably thinking how can a simple extension steal my data?
Some examples of information that it can collect are:
When users install these extensions, Glassworm can:
It's frightening and when I read the news on BleepingComputer I was shocked to see just how many developers' systems are getting compromised. Your probably thinking how can a simple extension steal my data?
What is Glassworm?
The Glassworm malware is a type of malware that has been embedded within malicious/fake extensions by cybercriminals. It works when a developer downloads/installs one of these type of malicious extensions then Glassworm malware gets downloaded onto the developer's system and begins to collect sensitive information.Some examples of information that it can collect are:
- Github Passwords
- VS Code Login Token and Marketplace Token
- Crypto Wallet Information
- Developer Account Contact Information
What Happened In This Third Attack?
In this third incident, researchers have discovered 24 more malicious VS Code packages. The new extensions all pretended to be something useful such as tools for React, Flutter, YAML file editing, themes and icons.When users install these extensions, Glassworm can:
- Establish a covert link between the hacker's server and the user's computer
- Take control of the user's computer
- Serve as a means for the hacker to route hidden data through the user's computer
What Can Be Done To Prevent This From Happening
You should take the following preventative measures:- Examine your installed extensions and delete anything questionable
- Disable auto-updating of extension
- Install only reputable and established extensions
- Stay current with your industry and check security information regularly