TigerJack malicious VS Code extension campaign
Campaign
Summary
Hide ▲
Show ▼
TigerJack is running a coordinated, systematic campaign that published at least 11 legitimate-looking VS Code extensions since early 2025, creating a supply-chain risk for developers who install them. The extensions were built to look useful while enabling source-code theft, cryptomining, and remote backdoors. The actor also republished the same malicious code under new names after takedowns, showing sustained operational continuity.
Related Happenings
Mini Shai-Hulud npm supply-chain malware wave
Malware Activity
H score68
First: 12.05.2026 14:07
Last: 12.05.2026 14:07
Sources 1
About this happening:
The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Mini Shai-Hulud npm supply-chain malware wave
Malware ActivityAbout this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Latest development: 09.06.2026 18:42
On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.
GlassWorm OpenVSX sleeper extension campaign
Campaign
H score45
First: 28.04.2026 00:41
Last: 28.04.2026 00:41
Sources 1
About this happening:
The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm OpenVSX sleeper extension campaign
CampaignAbout this happening: The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm v2 cloned VS Code extension loaders
Malware Activity
H score30
First: 27.04.2026 14:23
Last: 27.04.2026 14:23
Sources 1
About this happening:
The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
GlassWorm v2 cloned VS Code extension loaders
Malware ActivityAbout this happening: The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
GlassWorm Zig dropper infecting developer IDEs
Malware Activity
H score29
First: 10.04.2026 16:23
Last: 10.04.2026 16:23
Sources 1
About this happening:
The GlassWorm malware set now uses a Zig dropper that can silently infect all VS Code-based IDEs on a developer's machine, widening the reach of the compromise. The pa...
GlassWorm Zig dropper infecting developer IDEs
Malware ActivityAbout this happening: The GlassWorm malware set now uses a Zig dropper that can silently infect all VS Code-based IDEs on a developer's machine, widening the reach of the compromise. The pa...
GlassWorm open-source supply-chain campaign targeting developers
Campaign
H score46
First: 14.03.2026 14:55
Last: 14.03.2026 14:55
Sources 1
About this happening:
GlassWorm shifted from hidden Open VSX extension updates into a broader GitHub, npm, and VS Code/OpenVSX supply-chain campaign. Early reporting said seemingly...
GlassWorm open-source supply-chain campaign targeting developers
CampaignAbout this happening: GlassWorm shifted from hidden Open VSX extension updates into a broader GitHub, npm, and VS Code/OpenVSX supply-chain campaign. Early reporting said seemingly...
Latest development: 17.03.2026 23:42
GlassWorm renewed its supply-chain campaign against GitHub, npm, and VSCode/OpenVSX, with researchers identifying 433 compromised components this month across 200 GitHub Python repositories, 151 GitHub JS/TS repositories, 72 VSCode/OpenVSX extensions, and 10 npm packages. The operators compromised GitHub accounts to force-push malicious commits, published obfuscated code using invisible Unicode characters, and used Solana blockchain transactions as C2 to deliver a Node.js runtime and a JavaScript-based information stealer that targets cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment data.
Timeline
-
15.10.2025 17:16 3 articles · 9mo ago
TigerJack malicious VS Code extension campaign
Initial DisclosureSince early 2025, TigerJack used multiple publisher accounts to seed legitimate-looking extensions in VS Code Marketplace and Open VSX. The early phase focused on gaining trust and install base before malicious features and republishing steps expanded the operation.
Show sources
- Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks — thehackernews.com — 15.10.2025 17:16
- Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks — thehackernews.com — 15.10.2025 17:16
- Malicious VS Code Extensions Deploy Advanced Infostealer — www.infosecurity-magazine.com — 09.12.2025 18:45