Carnival - 7,531,359 breached accounts - RedPacket Security

In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator

RedPacket Security

(socket.dev) Escalation of GlassWorm Campaign: Sleeper Extensions Target Open VSX Marketplace with Advanced Evasion Techniques

GlassWorm campaign escalates with 73 sleeper extensions targeting Open VSX, using advanced evasion and transitive delivery techniques. At least six extensions activated, others flagged as high-confidence sleepers.

In brief - The GlassWorm threat actor is exploiting the Open VSX marketplace with impersonation extensions that initially appear benign but are later weaponized. The campaign uses social engineering, cloned listings, and multi-stage delivery to evade detection, posing a significant supply chain risk to developers.

Technically - GlassWorm employs sleeper extensions mimicking legitimate tools, leveraging `extensionPack` and `extensionDependencies` for transitive malware delivery. Payloads include GitHub-hosted VSIX files, obfuscated JavaScript, and bundled `.node` binaries with embedded GitHub release URLs. The campaign resolves CLI paths for multiple IDEs (VS Code, Cursor, VSCodium) and uses dead-drop channels like Solana transaction memos for runtime payload retrieval. Obfuscation techniques, such as encrypted URL decoding at runtime, further hinder detection.

Source: https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm

#Cybersecurity #ThreatIntel

73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations

Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.

Socket
[INCRANSOM] - Ransomware Victim: krauseundco - RedPacket Security

NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating

RedPacket Security
Cobalt Strike Beacon Detected - 43[.]143[.]242[.]10:5555 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security
Cobalt Strike Beacon Detected - 156[.]245[.]144[.]203:4443 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security
Cobalt Strike Beacon Detected - 106[.]75[.]215[.]96:8081 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security
Cobalt Strike Beacon Detected - 139[.]224[.]16[.]185:1234 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security
Cobalt Strike Beacon Detected - 103[.]117[.]120[.]98:5555 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security
Cobalt Strike Beacon Detected - 47[.]122[.]47[.]221:8880 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security
Cobalt Strike Beacon Detected - 47[.]76[.]96[.]68:5555 - RedPacket Security

Cobalt Strike Beacon Detection Alerts

RedPacket Security