• bitcoinBitcoin (BTC) $ 81,086.00
  • ethereumEthereum (ETH) $ 2,351.19
  • tetherTether (USDT) $ 0.999768
  • xrpXRP (XRP) $ 1.47
  • bnbBNB (BNB) $ 659.40
  • usd-coinUSDC (USDC) $ 0.999733
  • solanaSolana (SOL) $ 95.71
  • tronTRON (TRX) $ 0.351219
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • dogecoinDogecoin (DOGE) $ 0.110321
  • whitebitWhiteBIT Coin (WBT) $ 60.00
  • usdsUSDS (USDS) $ 0.999747
  • cardanoCardano (ADA) $ 0.285155
  • hyperliquidHyperliquid (HYPE) $ 43.23
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 579.94
  • leo-tokenLEO Token (LEO) $ 10.09
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • bitcoin-cashBitcoin Cash (BCH) $ 461.77
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 10.77
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 409.68
  • the-open-networkToncoin (TON) $ 2.39
  • canton-networkCanton (CC) $ 0.156165
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • stellarStellar (XLM) $ 0.171022
  • suiSui (SUI) $ 1.37
  • litecoinLitecoin (LTC) $ 59.60
  • susdssUSDS (SUSDS) $ 1.08
  • avalanche-2Avalanche (AVAX) $ 10.37
  • daiDai (DAI) $ 0.999584
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • usd1-wlfiUSD1 (USD1) $ 0.998869
  • hedera-hashgraphHedera (HBAR) $ 0.098014
  • memecoreMemeCore (M) $ 3.25
  • wethWETH (WETH) $ 2,268.37
  • ethena-usdeEthena USDe (USDE) $ 0.999557
  • shiba-inuShiba Inu (SHIB) $ 0.000007
  • rainRain (RAIN) $ 0.007598
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • crypto-com-chainCronos (CRO) $ 0.073989
  • bittensorBittensor (TAO) $ 326.28
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,709.45
  • global-dollarGlobal Dollar (USDG) $ 0.999765
  • uniswapUniswap (UNI) $ 4.02
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • polkadotPolkadot (DOT) $ 1.40
  • mantleMantle (MNT) $ 0.708181
  • pax-goldPAX Gold (PAXG) $ 4,714.53
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.068986
  • nearNEAR Protocol (NEAR) $ 1.61
  • ondo-financeOndo (ONDO) $ 0.416669
  • pepePepe (PEPE) $ 0.000004
  • internet-computerInternet Computer (ICP) $ 3.39
  • okbOKB (OKB) $ 88.68
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.715837
  • skySky (SKY) $ 0.079625
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pi-networkPi Network (PI) $ 0.175239
  • falcon-financeFalcon USD (USDF) $ 0.996803
  • htx-daoHTX DAO (HTX) $ 0.000002
  • aaveAave (AAVE) $ 102.38
  • ethereum-classicEthereum Classic (ETC) $ 9.90
  • ripple-usdRipple USD (RLUSD) $ 0.999897
  • bitget-tokenBitget Token (BGB) $ 2.16
  • usddUSDD (USDD) $ 0.999839
  • morphoMorpho (MORPHO) $ 2.16
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999101
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ethenaEthena (ENA) $ 0.134850
  • algorandAlgorand (ALGO) $ 0.130170
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • kucoin-sharesKuCoin (KCS) $ 8.52
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.103890
  • quant-networkQuant (QNT) $ 75.62
  • render-tokenRender (RENDER) $ 2.04
  • kaspaKaspa (KAS) $ 0.038450
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 2.03
  • united-stablesUnited Stables (U) $ 0.997740
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.24
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.08
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • aptosAptos (APT) $ 1.20
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.77
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • worldcoin-wldWorldcoin (WLD) $ 0.285656
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • filecoinFilecoin (FIL) $ 1.18
  • nexoNEXO (NEXO) $ 0.920279
  • wbnbWrapped BNB (WBNB) $ 759.61
  • arbitrumArbitrum (ARB) $ 0.144199
  • jupiter-exchange-solanaJupiter (JUP) $ 0.268917
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • gatechain-tokenGate (GT) $ 7.53
  • siren-2Siren (SIREN) $ 1.13
  • pump-funPump.fun (PUMP) $ 0.002212
  • stable-2​​Stable (STABLE) $ 0.034240
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.008767
  • justJUST (JST) $ 0.084353
  • bonkBonk (BONK) $ 0.000008
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • vechainVeChain (VET) $ 0.007944
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010766
  • venice-tokenVenice Token (VVV) $ 14.71
  • usdtbUSDtb (USDTB) $ 0.999091
  • dashDash (DASH) $ 48.59
  • beldexBeldex (BDX) $ 0.079642
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • xdce-crowd-saleXDC Network (XDC) $ 0.030812
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ousgOUSG (OUSG) $ 115.18
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.912420
  • official-trumpOfficial Trump (TRUMP) $ 2.51
  • ghoGHO (GHO) $ 0.999773
  • clbtcclBTC (CLBTC) $ 76,920.00
  • dexeDeXe (DEXE) $ 12.39
  • hash-2Provenance Blockchain (HASH) $ 0.010888
  • midnight-3Midnight (NIGHT) $ 0.033376
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.245578
  • usual-usdUsual USD (USD0) $ 0.998308
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000096
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.63
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • skyaiSkyAI (SKYAI) $ 0.534294
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • yldsYLDS (YLDS) $ 1.00
  • tbtctBTC (TBTC) $ 70,942.00
  • sei-networkSei (SEI) $ 0.076856
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • a7a5A7A5 (A7A5) $ 0.012931
  • aerodrome-financeAerodrome Finance (AERO) $ 0.535952
  • blockstackStacks (STX) $ 0.268868
  • true-usdTrueUSD (TUSD) $ 0.999851
  • chilizChiliz (CHZ) $ 0.045974
  • edgexedgeX (EDGE) $ 1.30
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • euro-coinEURC (EURC) $ 1.18
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.449698
  • spx6900SPX6900 (SPX) $ 0.472867
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • injective-protocolInjective (INJ) $ 4.32
  • tezosTezos (XTZ) $ 0.399811
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • monadMonad (MON) $ 0.035922
  • celestiaCelestia (TIA) $ 0.461409
  • adi-tokenADI (ADI) $ 4.02
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • usdgoUSDGO (USDGO) $ 1.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • build-onBUILDon (B) $ 0.415253
  • kite-2Kite (KITE) $ 0.177307
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • curve-dao-tokenCurve DAO (CRV) $ 0.262379
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997215
  • ether-fiEther.fi (ETHFI) $ 0.471755
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • sun-tokenSun Token (SUN) $ 0.020422
  • layerzeroLayerZero (ZRO) $ 1.52
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • usxUSX (USX) $ 0.999948
  • apxusdapxUSD (APXUSD) $ 0.999908
  • humanityHumanity (H) $ 0.202428
  • flokiFLOKI (FLOKI) $ 0.000038
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • doublezeroDoubleZero (2Z) $ 0.103272
  • lido-daoLido DAO (LDO) $ 0.418835
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • jasmycoinJasmyCoin (JASMY) $ 0.007174
  • optimismOptimism (OP) $ 0.164342
  • noonNoon (NOON) $ 0.751949
  • gnosisGnosis (GNO) $ 133.72
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • labLAB (LAB) $ 4.57
  • kinesis-goldKinesis Gold (KAU) $ 147.69
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • conflux-tokenConflux (CFX) $ 0.067129
  • bitcoin-svBitcoin SV (BSV) $ 17.49
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • pyth-networkPyth Network (PYTH) $ 0.060208
  • zebec-networkZebec Network (ZBCN) $ 0.003523
  • decredDecred (DCR) $ 19.65
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Hacker target the OpenVSX ecosystem to steal crypto wallets

0 16

Hacker target the OpenVSX ecosystem to steal crypto wallets

GlassWorm, a known malware, has put 73 harmful extensions into OpenVSX’s registry. Hackers use it to steal developers’ crypto wallets and other data.

Security researchers found that six extensions have already turned into active payloads. The extensions were uploaded as fake copies of well-known listings that weren’t harmful. According to a report from Socket, the bad code comes in a later update.

GlassWorm malware attacks crypto devs

In October 2025, GlassWorm first appeared. It used invisible Unicode characters to hide code intended to steal crypto wallet data and developer credentials. The campaign has since spread to npm packages, GitHub repositories, the Visual Studio Code Marketplace, and OpenVSX.

A wave hit hundreds of repositories and dozens of extensions in the middle of March 2026, but its size caught people’s attention. Several research groups noticed the activity early on and helped stop it.

The attackers appear to have changed their approach. The latest batch doesn’t embed malware right away; instead, it uses a delayed activation model. It sends a clean extension, builds an install base, and then sends a bad update.

“Cloned or impersonating extensions are first published without an obvious payload, then later updated to deliver malware,” Socket researchers said.

Security researchers found three ways to deliver the malicious code across the 73 extensions. One way is to use a second VSIX package from GitHub while the program is running and install it using CLI commands. Another method loads platform-specific compiled modules like [.]node files that contain the core logic, including routines for getting more payloads.

A third way uses heavily obfuscated JavaScript that decodes at runtime to download and install malicious extensions. It also has encrypted or fallback URLs for getting the payload.

The extensions look a lot like genuine listings.

In one case, the attacker copied the icon of the genuine extension and gave it a name and description that were almost the same. The publisher name and the unique identifier are what set them apart, but most developers don’t look closely at these things before installing.

GlassWorm is built to go after access tokens, crypto wallet data, SSH keys, and information about the developer environment.

Crypto wallets are continuously under attack from hackers

The threat goes beyond just crypto wallets. A different but related incident shows how supply chain attacks can spread through devs infrastructure.

On April 22, the npm registry hosted a bad version of Bitwarden’s CLI for 93 minutes under the official package name @bitwarden/cli@2026.4.0. JFrog, a security company, found that the payload stole GitHub tokens, npm tokens, SSH keys, AWS and Azure credentials, and GitHub Actions secrets.

JFrog’s analysis found that the hacked package modified the install hook and binary entrypoint to load the Bun runtime and run an obfuscated payload, both during installation and while running.

According to the company’s own records, Bitwarden has more than 50,000 businesses and 10 million users. Socket linked that attack to a bigger campaign tracked by Checkmarx researchers, and Bitwarden confirmed the connection.

The problem relies on how npm and other registries operate. Attackers exploit the time between when a package is published and when its contents are checked.

Sonatype found about 454,600 new malicious packages infesting registries in 2025. Threat actors looking to gain access to crypto custody, DeFi, and token launchpads have begun targeting registries and releasing malicious workflows.

For developers who installed any of the 73 flagged OpenVSX extensions, Socket recommends rotating all secrets and cleaning their development environments.

The next thing to watch is whether the remaining 67 dormant extensions activate in the coming days, and whether OpenVSX implements additional review controls for extension updates.

Source

Leave A Reply

Your email address will not be published.