Security Threats Emerge from Malicious and AI-Generated Extensions on Developer Platforms

1 min read
Source: The Hacker News
Security Threats Emerge from Malicious and AI-Generated Extensions on Developer Platforms
Photo: The Hacker News
TL;DR Summary

Cybersecurity researchers have identified three malicious VS Code extensions linked to the GlassWorm campaign, which uses invisible Unicode characters to hide malware, steal credentials, and spread in a worm-like fashion. Despite removal efforts, the threat has resurfaced, leveraging blockchain-based command-and-control infrastructure to maintain resilience. The attack has affected victims worldwide, including a major Middle Eastern government, and has expanded to target GitHub repositories.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

86%

46263 words

Want the full story? Read the original article

Read on The Hacker News