#2
BleepingComputer
general
March 17, 2026 at 21:42 UTC
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
By Bill Toulas
AI Summary
The GlassWorm supply-chain campaign returned with coordinated attacks targeting hundreds of packages across GitHub, npm, and VSCode/OpenVSX extensions. This demonstrates the continued evolution of software supply chain attacks targeting developer ecosystems and highlights the need for enhanced package repository security.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →