Risky Bulletin Newsletter
October 22, 2025
Risky Bulletin: Clever worm hits the DevOps scene
Presented by
News Editor
Security researchers have spotted a second self-propagating worm that hit the DevOps space within the span of a month. The new threat is named GlassWorm and primarily targets the VS Code extensions space.
It is the second such threat after the Shai-Hulud worm that hit the npm JavaScript package repo in mid-September.
GlassWorm was spotted by Koi Security. It was first seen on the unofficial OpenVSX marketplace for VS Code extensions, but later spread to the official Microsoft VS Code store as well.