Seventy-three malicious extensions sitting quietly in the OpenVSX registry, waiting for an update signal to turn hostile. That’s the GlassWorm campaign, and it’s a precise illustration of what the threat model actually looks like right now: patient, pre-positioned, and designed to detonate inside environments that already trust the delivery mechanism. The ipban question here isn’t “should we block bad IPs?” It’s whether your edge controls are tuned to catch the callback traffic after a sleeper wakes up.

Pair that with an incomplete Windows patch leaving the door open to zero-click attacks, originally exploited by APT28 against Ukraine and EU targets, and you have two separate kill chains converging on the same defensive gap: the window between when something goes wrong and when your controls actually respond. That window is where attackers live. Closing it faster is the only game worth playing.
Why Sleeper Attacks Break Perimeter Assumptions
The GlassWorm sleeper model is deliberately designed to defeat signature-based detection at install time. The extension looks clean on arrival. No malicious payload, no suspicious network calls, no IOCs to match. The kill switch lives in the update mechanism. Once an update arrives carrying the weaponized payload, the malicious behavior begins, and by that point the tool is already trusted, already running inside developer workstations, and already past your perimeter.
This isn’t a new concept, but it’s getting more disciplined. The OpenVSX campaign targets developers specifically because developer machines are the richest pivot points in most organizations. They hold credentials, API keys, source code access, and direct pipelines into production infrastructure. A single compromised dev box can be worth more than a dozen compromised end-user machines.
The APT28 zero-click vulnerability compounds this. Zero-click means no user interaction required, which collapses the “train users not to click” defense entirely. When a patch is incomplete and the vuln stays live, your network-layer controls absorb load that was supposed to be carried by the OS vendor. That’s not hypothetical; that’s the current state for any Windows environment that applied the patch and assumed the issue was closed.
Both threats share one characteristic worth exploiting defensively: they generate outbound traffic. Sleeper extensions need to phone home. Exploited zero-click vulnerabilities need to establish C2 or exfiltrate data. That egress behavior is your detection opportunity, and edge-layer controls configured to catch it are the fastest response you have.
Harden the Edge Before the Next Update Drops
Blocking known-bad IPs reactively is table stakes. The smarter posture combines behavioral egress monitoring with aggressive default-deny on outbound connections from high-value machines. Here’s a concrete sequence that applies regardless of your stack:
- Audit extension inventories now. Pull a list of every VS Code or OpenVSX extension installed across developer endpoints. Cross-reference against the GlassWorm IOC list published by BleepingComputer. If you don’t have visibility into what’s installed on dev machines, that gap is urgent.
- Lock down extension auto-update behavior. In managed environments, disable automatic extension updates and route all updates through an internal approval queue. An extension can’t detonate a new payload if the update never arrives.
- Apply egress filtering on developer workstations. Developer machines have a well-understood set of outbound destinations: package registries, source control, CI/CD endpoints. Any connection outside that baseline deserves scrutiny. Configure firewall rules or a network proxy to log and alert on anomalous egress from those machines.
- Treat the incomplete APT28 patch as unpatched. Until a complete fix is confirmed, compensating controls matter. Restrict attack surface by limiting which services are externally reachable from affected Windows systems, and increase logging verbosity on those hosts.
- Enable automated IP-layer blocking on repeated callback attempts. A sleeper extension or post-exploitation tool that’s trying to establish C2 will generate repeated outbound connection attempts if the first ones fail. Behavioral blocking that fires on repeated failed egress attempts to new destinations catches that pattern without requiring a signature match.

Don’t Forget Internal Segments
Most egress filtering strategies focus on the north-south traffic leaving the network. Sleeper malware on a developer machine pivots east-west first. Make sure your internal segmentation is tight enough that a compromised dev box can’t freely scan or connect to adjacent systems. If your security hardening plans treat developer machines as a separate trust zone, this scenario is already in scope. If they’re sitting flat on the corporate network, that’s the actual fire to put out.
The Patience Problem in Threat Detection
Both the GlassWorm campaign and the APT28 zero-click exploitation reflect something worth internalizing: modern attackers are comfortable with patience. Seventy-three extensions sitting dormant until the right update arrives. A vulnerability left partially patched while defenders assume it’s closed. These aren’t smash-and-grab operations; they’re designed for environments where defenders are reactive and rely on point-in-time checks.
Incident response gets harder when the initial compromise is weeks or months old by the time it activates. The forensic trail is cold. The blast radius is harder to scope. Your threat detection posture needs to account for the fact that something in your environment may already be waiting. Continuous behavioral monitoring, network flow analysis, and aggressive logging retention are the controls that give you a fighting chance at catching dormant threats before they activate.
Threat protection frameworks built around blocking known-bad indicators will always lag behind campaigns that go clean until the moment they don’t. The investment worth making is in behavioral baselines: know what normal looks like for your high-value machines, so abnormal stands out even when there’s no signature to match against.
Seventy-three extensions is a lot of patience. Your defenses need to be faster than the attacker’s timer.
Sources
- GlassWorm malware attacks return via 73 OpenVSX “sleeper” extensions
- Incomplete Windows Patch Opens Door to Zero-Click Attacks
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
