LummaStealer Windows extension-delivery chain
Malware Activity
Summary
Hide ▲
Show ▼
A Windows payload chain now runs LummaStealer after malicious extension execution, putting cryptocurrency wallet data, browser credentials, and messaging app data at risk. The malware is delivered through a multi-stage script sequence rather than a direct binary launch. That makes the extension-install path a practical theft mechanism for affected users.
Related Happenings
GlassWorm v2 cloned VS Code extension loaders
Malware Activity
H score30
First: 27.04.2026 14:23
Last: 27.04.2026 14:23
Sources 1
About this happening:
The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
GlassWorm v2 cloned VS Code extension loaders
Malware ActivityAbout this happening: The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
GlassWorm Zig dropper infecting developer IDEs
Malware Activity
H score29
First: 10.04.2026 16:23
Last: 10.04.2026 16:23
Sources 1
About this happening:
The GlassWorm malware set now uses a Zig dropper that can silently infect all VS Code-based IDEs on a developer's machine, widening the reach of the compromise. The pa...
GlassWorm Zig dropper infecting developer IDEs
Malware ActivityAbout this happening: The GlassWorm malware set now uses a Zig dropper that can silently infect all VS Code-based IDEs on a developer's machine, widening the reach of the compromise. The pa...
DeepLoad credential-stealing malware activity with WMI persistence
Malware Activity
H score30
First: 31.03.2026 00:25
Last: 31.03.2026 00:25
Sources 1
About this happening:
The DeepLoad malware strain is stealing credentials immediately after infection, exposing stored browser passwords, live keystrokes, and active accounts in enter...
DeepLoad credential-stealing malware activity with WMI persistence
Malware ActivityAbout this happening: The DeepLoad malware strain is stealing credentials immediately after infection, exposing stored browser passwords, live keystrokes, and active accounts in enter...
GlassWorm open-source supply-chain campaign targeting developers
Campaign
H score46
First: 14.03.2026 14:55
Last: 14.03.2026 14:55
Sources 1
About this happening:
GlassWorm shifted from hidden Open VSX extension updates into a broader GitHub, npm, and VS Code/OpenVSX supply-chain campaign. Early reporting said seemingly...
GlassWorm open-source supply-chain campaign targeting developers
CampaignAbout this happening: GlassWorm shifted from hidden Open VSX extension updates into a broader GitHub, npm, and VS Code/OpenVSX supply-chain campaign. Early reporting said seemingly...
Latest development: 17.03.2026 23:42
GlassWorm renewed its supply-chain campaign against GitHub, npm, and VSCode/OpenVSX, with researchers identifying 433 compromised components this month across 200 GitHub Python repositories, 151 GitHub JS/TS repositories, 72 VSCode/OpenVSX extensions, and 10 npm packages. The operators compromised GitHub accounts to force-push malicious commits, published obfuscated code using invisible Unicode characters, and used Solana blockchain transactions as C2 to deliver a Node.js runtime and a JavaScript-based information stealer that targets cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment data.
InstallFix Claude Code malvertising campaign
Campaign
H score32
First: 06.03.2026 17:00
Last: 06.03.2026 17:00
Sources 1
About this happening:
InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for...
InstallFix Claude Code malvertising campaign
CampaignAbout this happening: InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for...
Timeline
-
13.09.2025 17:00 2 articles · 10mo ago
WhiteCobra Windows chain delivers LummaStealer
Technical Analysis UpdateWhiteCobra's Windows extension-delivery chain stages a next payload from Claudflare Pages and uses a PowerShell script, a Python script, and shellcode to launch LummaStealer after extension execution; on Windows, the infostealer targets cryptocurrency wallet apps, web extensions, browser-stored credentials, and messaging app data.
Show sources
- 'WhiteCobra' floods VSCode market with crypto-stealing extensions — www.bleepingcomputer.com — 13.09.2025 17:00
- 'WhiteCobra' floods VSCode market with crypto-stealing extensions — www.bleepingcomputer.com — 13.09.2025 17:00