Originally published December 10, 2025
Editor’s Note: This article was originally published by Koi Security on December 10, 2025. Following Palo Alto Networks' acquisition of Koi Security, this research has been migrated to the Palo Alto Networks Threat Research hub. The findings below detail historical observations from the November 2025 GlassWorm campaign wave.
Key Takeaways
- Shift to Compiled Loaders: GlassWorm abandoned invisible Unicode character obfuscation in favor of compiled native Rust binaries (.node Node.js addons) to complicate static analysis and reverse engineering.
- Dual-Marketplace Targeting: The threat actor expanded beyond the OpenVSX Registry to target Microsoft’s official Visual Studio Code Marketplace.
- Typosquatting & Update Poisoning: Malicious extensions initialised with benign functional code to establish downloads before pushing update releases containing native loaders.
- Resilient C2 Infrastructure: The campaign maintained its core Solana blockchain command-and-control (C2) infrastructure and Google Calendar fallback mechanisms from prior waves.
Overview of the November 2025 Wave
The GlassWorm campaign resurfaced in late November 2025. Following initial public disclosures in October 2025, which observed over 45,000 infected machines, the campaign briefly paused. On November 22, 2025, activity resumed when an associated Solana wallet executed new transactions pointing to a refreshed C2 IP structure.
Within days, malicious developer extensions appeared across both the OpenVSX Registry and Microsoft’s official Visual Studio Code Marketplace.
While the fundamental attack chain and underlying Solana C2 infrastructure remained identical to previous iterations, the actor overhauled their delivery mechanism to evade detection.
Shift from Unicode Obfuscation to Native Binaries
In earlier campaign waves, GlassWorm relied on steganographic techniques using invisible Unicode characters embedded in JavaScript files to hide payload staging code.
In the November 2025 wave, the threat actor replaced invisible Unicode obfuscation with compiled Rust binaries. All payload handling capabilities—including Solana C2 lookups, payload decryption, and execution—were moved into native .node binaries.
To inspect the underlying mechanics, defenders must perform binary reverse engineering on compiled native code rather than decoding high-level JavaScript.
Case Study: Iconesvscode Impersonation
The extension bphpburnsus.iconesvscode on Microsoft's Visual Studio Code Marketplace impersonated the popular vscode-icons extension.
- Version 12.15.0 (Clean): Delivered legitimate theme functionality consisting of 22,765 lines of JavaScript.
- Versions 12.15.1 and 12.15.2 (Poisoned): The legitimate codebase was purged and reduced to 33 lines of JavaScript.


The reduced JavaScript acted purely as a loader: it identified the host operating system and executed the corresponding compiled native binary.

Technical Analysis of Native Implants
The native binaries were distributed as Node.js native addons named darwin.node (macOS) and os.node (Windows).

Each implant binary was approximately 2.4 MB in size. Once loaded into memory by Node.js, the binary executed the following sequence:
- C2 Resolution via Solana: Queries the Solana blockchain to dynamically fetch updated C2 configuration data.
- Payload Staging: Connects to remote staging servers to download Base64-encoded, AES-256-CBC encrypted payloads.
- Fallback C2 Routing: If primary C2 queries fail, the binary uses Google Calendar entries as an operational fallback channel.
Developer Traces in macOS Binaries
Compilation artifacts recovered from darwin.node revealed explicit developer directory paths:
| /Users/davidioasd/Downloads/rust_implant/target/release/deps/librust_implant.dylib
/Users/davidioasd/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/http-body-util-0.1.3/src/combinators/collect.rs |
|---|
The username string davidioasd matches artifact patterns identified during the October 2025 initial wave, confirming continuity of author and operational infrastructure.
Defense and Platform Mitigation
Software supply chain threats targeting developer tools leverage trusted ecosystem channels like IDE marketplaces. Security teams must implement Agentic Endpoint Security across dependency channels and developer environments.
Organizations using Cortex® Agentic Endpoint Security can detect unapproved developer tooling, suspicious AI behavior, and anomalous agentic artifacts within employee workstations.
Indicators of Compromise (IOCs)
Note: The extension identifiers and infrastructure addresses below reflect historical findings from the November 2025 investigation. Network IOCs have been defanged.
Malicious Extension Identifiers
| OpenVSX Registry | Microsoft VSCode Marketplace |
|---|---|
| bphpburn.icons-vscode | bphpburnsus.iconesvscode |
| clangdcode.clangd-vscode | iconkieftwo.icon-theme-materiall |
| csvmech.csv-sql-tsv-rainbow | clangdcode.clangd-vsce |
| cweijamysq.sync-settings-vscode | codevsce.codelddb-vscode |
| eamodas.shiny-vscode | csvmech.csvrainbow |
| flutcode.flutter-extension | cweijamysq.sync-settings-vscode |
| iconkief.icon-theme-material | dart-vsc.code-dart |
| msjsdreact.react-native-vscode | flutcode.flutter-extension |
| saoudrizvsce.claude-dev | klustfix.kluster-code-verify |
| saoudrizvsce.claude-devsce | lyywemhan.code-formatter-and-minifier-vscode |
| solblanco.svelte-vscode | msjsdreact.react-native-vsce |
| svltsweet.svetle-for-cursor | prettier-vsc.vsce-prettier |
| tailwind-nuxt.tailwindcss-for-react | prisma-inc.prisma-studio-assistance |
| vitalik.solidity | redmat.vscode-quarkus-pro |
| yamlcode.yaml-vscode-extension | saoudrizvsce.claude-devsce |
| solblanco.svetle-vsce | |
| vims-vsce.vscode-vim | |
| vsceue.volar-vscode | |
| yamlcode.yaml-vscode-extension |
Rust Implants (SHA-256)
macOS (darwin.node):
- 026873b940176d103d45b41c9fba73f14cfcaca60e3117be81d2eadef85a4d17
- 9bd105ce732218f30719fd69d4555967b362d37f4f6aec04741c18aaa7411a73
- fb07743d139f72fca4616b01308f1f705f02fda72988027bc68e9316655eadda
Windows (os.node):
- cbb3f830731fe2c9194f7fe5aa55479cffdae184039b0df078b1394209d7a49f
- 29875e74f033c819c1acab58ef08bc35646aab5f4a2747ee0933ca41150d7099
- 6ebeb188f3cc3b647c4460c0b8e41b75d057747c662f4cd7912d77deaccfd2f2
Network Infrastructure
Command & Control Infrastructure:
- 217.69.13[.]229
- 45.76.45[.]151
- 45.32.151[.]157
- 107.191.62[.]170
Exfiltration Servers:
- 104.238.191[.]54
- 108.61.208[.]161