<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Malware on AI VOID</title><link>https://ai-blog.noorshomelab.dev/tags/malware/</link><description>Recent content in Malware on AI VOID</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 15 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ai-blog.noorshomelab.dev/tags/malware/index.xml" rel="self" type="application/rss+xml"/><item><title>Glassworm Malware: Latest Updates &amp;amp; News Digest</title><link>https://ai-blog.noorshomelab.dev/news/glassworm-malware-updates/</link><pubDate>Sun, 15 Feb 2026 00:00:00 +0000</pubDate><guid>https://ai-blog.noorshomelab.dev/news/glassworm-malware-updates/</guid><description>&lt;h2 id="tldr"&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;Glassworm malware has made a significant return, marking its third wave of attacks primarily targeting &lt;strong&gt;Visual Studio Code (VS Code) packages and extensions&lt;/strong&gt;. Developers are urged to exercise extreme caution.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Third Wave Active:&lt;/strong&gt; Glassworm has resurfaced on both the OpenVSX and Microsoft Visual Studio Marketplaces.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;VS Code Extensions Targeted:&lt;/strong&gt; Malicious extensions are the primary infection vector, impacting developer environments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self-Propagating &amp;amp; Ransomware:&lt;/strong&gt; The malware exhibits self-propagating capabilities and includes basic ransomware functionalities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Supply Chain Risk:&lt;/strong&gt; This resurgence highlights critical vulnerabilities in the software supply chain for developer tools.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Immediate Action Required:&lt;/strong&gt; Developers should audit installed extensions, prioritize trusted sources, and implement robust security practices.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="key-developments-glassworms-third-wave"&gt;Key Developments: Glassworm&amp;rsquo;s Third Wave&lt;/h2&gt;
&lt;h3 id="glassworms-resurgence-in-vs-code-marketplaces"&gt;Glassworm&amp;rsquo;s Resurgence in VS Code Marketplaces&lt;/h3&gt;
&lt;p&gt;The Glassworm campaign, first identified in October 2025, has re-emerged in its third wave, actively compromising extensions available on both the OpenVSX Registry and the official Microsoft Visual Studio Marketplace. This widespread distribution channel significantly increases the potential for developer infection.&lt;/p&gt;</description></item><item><title>GlassWorm Malware Infection: Complete Troubleshooting Guide</title><link>https://ai-blog.noorshomelab.dev/troubleshooting/glassworm-malware-infection-troubleshooting/</link><pubDate>Tue, 06 Jan 2026 00:00:00 +0000</pubDate><guid>https://ai-blog.noorshomelab.dev/troubleshooting/glassworm-malware-infection-troubleshooting/</guid><description>&lt;h2 id="what-is-this-error"&gt;What is This Error?&lt;/h2&gt;
&lt;p&gt;The &amp;ldquo;GlassWorm Malware Infection&amp;rdquo; refers to a sophisticated, self-spreading supply-chain attack that targets developers using the OpenVSX and Microsoft Visual Studio Code marketplaces. This malware typically injects itself into seemingly legitimate VS Code extensions, which developers then download and install. Once active, GlassWorm aims to steal sensitive credentials, cryptocurrency, and establish persistence on the infected system. It&amp;rsquo;s a critical security threat that can compromise development environments and intellectual property.&lt;/p&gt;</description></item></channel></rss>