Risky Bulletin: Clever worm hits the DevOps scene (VS Code)
risky.biz·8h·
Discuss: Hacker News
Flag this post

Risky Bulletin Newsletter

October 22, 2025

Written by

Catalin Cimpanu

Catalin Cimpanu

News Editor

** * This newsletter is brought to you by * ** Dropzone ** * . You can subscribe to an audio version of this newsletter as a podcast by searching for “Risky Business” in your podcatcher or subscribing via * ** this RSS feed ** * . * **

Security researchers have spotted a second self-propagating worm that hit the DevOps space within the span of a month. The new threat is named GlassWorm and primarily targets the VS Code extensions space.

It is the second such threat after the [Shai-Hulud worm ](https://unit42.paloaltonetworks.com/npm-supply-c…

Similar Posts

Loading similar posts...