Gate News reports that the security agency GoPlus has issued a warning indicating that GlassWorm has evolved from an early VS Code worm into a highly sophisticated supply chain attack framework that disguises itself as a Chrome extension to steal users’ sensitive data and cryptocurrency assets, with the threat scope continuously expanding.
The core of this attack relies on poisoning and covert code injection. Attackers manipulate npm and PyPI packages using special Unicode and PUA characters, embedding malicious loaders. These characters are difficult to identify in code review tools, allowing the malicious code to bypass traditional static analysis detection, contaminating the development environment from the source.
On the communication front, GlassWorm employs a more covert control method. It abandons traditional domain name servers and instead uses the Solana blockchain as a command and control channel, hiding instructions within on-chain transaction notes. This design enhances the attack infrastructure’s resistance to blocking, making it challenging to trace or cut off using conventional means.
At the endpoint, the attack is executed by disguising itself as a “Google Docs Offline” extension. This malicious plugin can steal browser cookies, clipboard content, and browsing history, while also possessing keystroke logging and screenshot capabilities, and can monitor activities on hardware wallets like Ledger and Trezor. Moreover, attackers may pop up phishing interfaces to lure users into entering their recovery phrases, thereby gaining direct control over digital assets.
GoPlus advises users to deploy detection tools capable of identifying hidden characters and to avoid installing software or plugins from unknown sources. Additionally, be vigilant about unusual transaction signatures and transfer requests. If a device is suspected of being compromised, disconnect it from the network immediately and change all related account credentials to minimize potential losses.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to
Disclaimer.
Related Articles
Solana Spot ETF Sees $1.17M Net Outflow as FSOL Records Inflows
Gate News message, April 26 — Solana spot ETFs recorded net outflows of $1.1736 million yesterday (April 24), according to SoSoValue data. The total assets under management for SOL spot ETFs reached $883 million as of reporting time, with a net asset ratio of 1.77% and cumulative net inflows of $1.0
GateNews4h ago
Solana Meme Coin Memecoin Breaks $12.23M Market Cap, Surges 37.3% in 24 Hours
Gate News message, April 26 — Memecoin, a Meme token on Solana, has surged 37.3% over the past 24 hours and breached a market capitalization of $12.23 million today, according to on-chain data monitoring.
BlockBeats notes that Meme coin trading carries substantial volatility and is largely driven b
GateNews8h ago
Solana Eyes $87 Breakout as Bullish Signals Strengthen
Solana sits near key resistance around $87 as on-chain activity and positive funding buoy bullish momentum; whale-led demand in derivatives supports a potential breakout. RSI >50 and positive MACD indicate rising upside, with a path toward $92–$97 and support near $77.
CryptoNewsLand19h ago
GSR Debuts BESO ETF With Bitcoin, Ethereum, Solana
GSR debuts BESO ETF with active strategy, adjusting Bitcoin, Ether, and Solana allocations weekly to outperform benchmarks.
ETF records nearly $5M in first-day volume, signaling early investor interest in diversified crypto investment products.
Launch aligns with growing ETF momentum as
CryptoFrontNews04-25 13:36
Solana Spot ETF Sees $1.14M Net Outflows Yesterday, FSOL Posts Gains While VSOL Declines
Gate News message, April 25 — Solana spot ETFs recorded a combined net outflow of $1.1364 million yesterday (April 24), according to SoSoValue data.
Fidelity Solana Fund ETF (FSOL) posted a single-day net inflow of $257,000 and has accumulated $158 million in historical net inflows. VanEck Solana E
GateNews04-25 09:46
U.S. Solana Spot ETFs Record $1.17M Net Outflows; Fidelity FSOL Posts Inflows
Gate News message, April 25 — According to SoSoValue data, U.S. Solana spot ETFs recorded a combined net outflow of $1.1736 million yesterday (April 24, ET).
Fidelity Solana Fund ETF (FSOL) posted a daily net inflow of $257,000, bringing its historical cumulative net inflows to $158 million.
GateNews04-25 02:46