GlassWorm Malware targets VS Code via three malicious extensions, harvesting credentials and using invisible code to spread. Despite attempts to remove it, the campaign persists, affecting various regions, including government entities. The malware showcases evolving attack techniques, such as utilizing blockchain for command/control. Security researchers identified a Russian-speaking attacker behind it, indicating significant risks to organizations using affected tools.
https://thehackernews.com/2025/11/glassworm-malware-discovered-in-three.html

