GlassWorm malware attacks return via 73 OpenVSX "sleeper" extensionsPosted by PrivacyWireA new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 "sleeper" extensions that turn malicious after an update. [...]1 repliestomspark wrote:This is exactly why you shouldn't install random extensions from untrusted repos. OpenVSX is great in theory but it's got zero gatekeeping compared to the official VS Code marketplace — sleeper malware is the inevitable result when you don't vet submissions properly.