Cybersecurity researchers at Koi Security have discovered the worldβs first self-propagating malware targeting VS Code extensions on the OpenVSX Marketplace. Dubbed GlassWorm, the threat marks a historic milestone in software supply chain attacks β combining invisible Unicode injection, blockchain-based C2 infrastructure, Google Calendar backup servers, and remote access trojan capabilities. As of October 19, 2025, at least 35,800 installations are confirmed compromised, with multiple infected extensions still active on both OpenVSX and Microsoftβs VS Code Marketplace.
The new worm, GlassWorm, represents an evolutionary leap in attack sophistication. It spreads automatically across developer ecosystems, harvesting credentials, draining cryptocurrency wallets, and transforming infected developer workstations into criminal proxy nodes.
βThis is one of the most sophisticated supply chain attacks we’ve ever analyzed. And it’s spreading right now.β
At the heart of GlassWorm lies an unprecedented stealth tactic β invisible malicious code embedded via Unicode variation selectors.
When analyzing the CodeJoy extension (version 1.8.3), Koiβs risk engine flagged abnormal network and credential access behavior. What followed stunned researchers:

βSee that massive gap between lines 2 and 7? Thatβs not empty space. Thatβs malicious code. Encoded in unprintable Unicode characters that literally donβt render in your code editor.β
This means the malware isnβt obfuscated β itβs literally invisible to human eyes and most automated scanners. Even GitHubβs diff viewer and VS Codeβs syntax highlighting show nothing unusual.
βThe attacker used Unicode variation selectorsβ¦ To a developer doing code review, it looks like blank lines. To static analysis tools scanning for suspicious code, it looks like nothing at all. But to the JavaScript interpreter? Itβs executable code.β
The attack fundamentally challenges the software communityβs reliance on manual code review.
βWeβve built entire systems around the assumption that humans can review code. GlassWorm just proved that assumption wrong.β
Once decoded, the βinvisibleβ payload revealed a command infrastructure.
βThe malware uses the Solana blockchain as its command and control infrastructure.β
Each infected system queries the blockchain for transactions from a hardcoded wallet address, reading the transaction memo field to retrieve a base64-encoded link to its next payload.
Koi explains:
βImmutable, anonymous, censorship-resistant, dynamic, and cheap β the Solana blockchain just… exists.β
This blockchain-based C2 system means the malware cannot be taken down by domain seizures or takedown requests. Even if defenders block a known IP, the attacker simply posts a new Solana transaction pointing to a new payload.
After decrypting the Solana payload, analysts found another surprise β a Google Calendar event being used as a backup command server.
βThe malware reaches out to this Google Calendar event as a backup C2 mechanism. And guess whatβs in the event title? Another base64-encoded URL pointing to yet another encrypted payload.β
The researchers highlight the brilliance of this redundancy:
βFree and legitimate (no oneβs blocking Google Calendar)β¦ Another unkillable infrastructure piece.β
Meanwhile, GlassWorm actively hunts for credentials across NPM, GitHub, OpenVSX, and 49 different cryptocurrency wallet extensions β from MetaMask and Phantom to Coinbase Wallet.
βThe malware is hunting for credentials: NPM tokens, GitHub tokens, Git credentialsβ¦ 49 different cryptocurrency wallet extensions.β
Decryption of the so-called βzombi_payloadβ revealed ZOMBI, a multi-functional remote access trojan (RAT) that transforms infected systems into proxy nodes and hidden remote desktops.
ZOMBI capabilities include:
- SOCKS proxy creation β turning infected devices into anonymized routing nodes.
- WebRTC P2P communication β establishing firewall-bypassing direct control channels.
- BitTorrent DHT distribution β decentralized command propagation.
- Hidden VNC (HVNC) β stealth remote desktop access invisible to the user.
βHVNC gives the attacker complete remote desktop access to your machineβbut itβs hidden. It runs in a virtual desktop that doesnβt appear in Task Manager and operates completely invisibly.β
The implications are severe:
βYour developer workstation… just became a proxy node for criminal activity.β
What distinguishes GlassWorm from traditional supply chain compromises is its autonomous replication.
βThe self-replication cycle uses stolen NPM, GitHub, and OpenVSX credentials to compromise more packages and extensions automatically.β
Every new victim becomes a launchpad for additional infections, creating an exponential growth model reminiscent of biological viruses.
βAttackers have figured out how to make supply chain malware self-sustaining. Theyβre building worms that can spread autonomously through the entire software development ecosystem.β
As of October 19, 2025, the infection is still active.
βSeven OpenVSX extensions compromised on October 17, 2025β¦ Ten extensions still actively distributing malware as you read this.β
Because VS Code extensions auto-update, users received the malicious version automatically β no action required.
βWhen CodeJoy pushed version 1.8.3 with invisible malware, everyone with CodeJoy installed got automatically updated to the infected version. No user interaction. No warning. Just silent, automatic infection.β
Koi Security warns:
βThis isnβt some theoretical attack or historical incident. GlassWorm is active right now.β
Related Posts:
- “Unicode QR Code Phishing”: The New Threat You Need to Know
- North Korean Hackers Deploy RustDoor and Koi Stealer to Target Cryptocurrency Developers on macOS
- Obfuscated Malware Delivered via Google Calendar Invites and Unicode PUAs
- Stealthy WordPress Malware Uncovered: SEO Spam Plugin Mimics Your Domain to Evade Detection
- Solana Drainer Source Code Leak Reveals MS Drainer Connection, Underscores Growing Threat to Crypto Users
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!