Springs are great, but making them out of plastic tends to come with some downsides, for fairly obvious reasons. Creating a compliant mechanism that can be 3D printed and yet which doesn’t permanently deform or wear out after a few uses is therefore a bit of a struggle. The complaint toggle mechanism that [neotoy] designed is said to have addressed those issues, with the model available on Printables for anyone to give a shake.
The model in question is a toggle, which is the commonly seen plastic or metal device that clamps down on e.g. rope or cord and requires you to push on it to have it release said clamping force. Normally these use a metal spring inside, but this version is fully 3D printable and thus forms a practical way to test this particular compliant mechanism with a variety of materials.
The internal spring is a printed spiral spring, with the example in the video printed in PETG. You can of course also print it in other materials for different durability and springiness properties. As noted in the video, PLA makes for a very poor spring material, so you probably want to skip that one.
We covered compliant mechanisms in the past for purposes like blasters, including some that you can only see under a microscope.
Shoppers looking for a good gaming machine these days are frequently met with component prices that continue to rise, with many top-of-the-line solutions that would have been affordable a few months ago being exceedingly expensive. Against this backdrop, the ASUS TUF Gaming F16 (2025) appears deceptively low-cost at $899.99 (was $1,299.99), as if it’s almost too good to be true.
When you launch a current game, the Intel Core i5 and the RTX 5050 graphics chip at 115 watts create an immediate impression. You can crank up the settings without worrying about it tanking – smooth frames and all, even in the most demanding parts of the game. Even with multitasking, everything runs well, with no juddering or latency.
READY FOR ANYTHING – Dive headfirst into gaming on Windows 11 powered by the Intel Core i5 Processor 13450HX and an NVIDIA GeForce RTX 5050 Laptop…
SUBTLE STYLING – The TUF Gaming F16 maintains its classic design, boasting a subtle embossed TUF logo on its sleek cover.
IMMERSIVE VISUALS – The TUF Gaming F16’s FHD+ 165Hz display with 100% sRGB color draws you into the action. Adaptive-Sync technology reduces lag…
In terms of build quality, this thing has it where it counts, as the chassis has passed all military-style endurance tests, drops, vibrations, and high temperatures, all the while being relatively lightweight for its size. Measuring around an inch thick at its narrowest point, it sports a strong metal lid and a reinforced frame, so you get a laptop that can withstand the rigors of daily use without a scratch.
Advertisement
The 16-inch panel is a beast of a screen, with a 165Hz refresh rate and a 16:10 aspect ratio, giving you a lot more vertical real estate than you’re used to, which is just what you need to get more done. Fast-paced gaming runs extremely well, while the anti-glare coating helps keep your eyes from tiring.
The battery life is actually rather impressive for a gaming laptop, thanks to its 90Wh cell. Doing simple tasks like browsing or streaming may give you several hours on a single charge, which is more than many people expected from this type of technology. With rapid charging, you can quickly top it up at the coffee shop and be ready to go for the remainder of the day.
In terms of connectivity, you’ll have all you need to handle almost any situation without having to deal with clunky USB hubs. Connect an external monitor via HDMI or USB-C, connect to a wired network via Ethernet when speed is critical, or plug in a controller or headphones via USB. Finally, upgrades are the only thing that will keep your laptop useful for years to come. You begin with two memory slots (16GB of DDR5 to get you started) and the ability to add more. A PCIe drive has 512GB of storage by default, although more can be added if necessary.
‘The transaction complied fully with applicable law,’ Meta said in a statement.
China has blocked Meta’s $2bn acquisition of AI start-up Manus. In a brief statement, the country’s National Development and Reform Commission (NDRC) said that the decision to prohibit foreign investment in Manus was made in accordance with Chinese laws. It has asked the parties to withdraw from the acquisition.
In a statement to SiliconRepublic.com, a spokesperson for Meta said: “The transaction complied fully with applicable law. We anticipate an appropriate resolution to the inquiry.” Meta did not confirm whether it would push back against the decision.
China’s decision hinders Meta’s massive AI plans to play catch-up with its Big Tech competitors. The company has spent billions to acquire businesses, hire expensive executives and realign its priorities around AI. Last week, the Facebook owner decided to cut 8,000 jobs in a bid to run “more efficiently” and “offset the other investments” it’s making.
Advertisement
The company, which has budgeted $135bn in spending this year, committed to purchasing Manus late last year, followed by the viral Moltbook platform in March for an undisclosed amount.
Manus employees and executives have joined Meta, while investors including Tencent Holdings, ZhenFund and Hongshan have already received their proceeds from the acquisition, sources have told Bloomberg.
A person familiar with the matter told the Financial Times that the NDRC’s decision was “harsh”, and that it carries a “strong intention to stop follow-on deals” similar to Manus.
“In reality, it’s hard to unwind a done deal, so it is more about verbal warnings on similar deals and the leveraging building before the Xi-Trump summit,” the source added. FT has since removed the latter half of this quote. US president Donald Trump is set to meet with his Chinese counterpart Xi Jinping next month.
Advertisement
Manus is headquartered in Singapore, but has a Chinese parent company called Butterfly Effect Technology. Meta acquired the company after a $75m funding round last April that valued it at $500m.
As per the now contested acquisition deal, Meta would operate and sell the Manus service, as well as integrate it into its own products. However, Manus would still be able to sell its subscriptions through its own app and website.
In February, the start-up launched ‘Manus Agents’, personal AI agents that perform similarly to the Austrian-made open source OpenClaw. The agents, which debuted on Telegram that month, had been expanded to WhatsApp shortly after. Meta did not confirm if China’s decision would affect Manus Agents on WhatsApp.
The Chinese Ministry of Commerce launched an investigation shortly following the Meta acquisition to determine whether it violated the country’s laws on technology exports and outbound investment. According to the rules, the Chinese government needs to approve the export of certain technologies, including AI.
Advertisement
Bloomberg recently reported that Chinese agencies told the country’s key AI firms that they should reject capital with US origins unless explicitly approved.
Updated, 4.02pm, 27 April 2026: This article was amended to mention that a quote given to the Financial Times has since been edited.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Released in 2014 to protect FIFA 15 from piracy and circumvention, Denuvo built a reputation as the toughest protection layer in PC gaming. Over the years, various groups and independent developers managed to break the technology on a case-by-case basis, producing cracked versions of individual games. That long-running contest now… Read Entire Article Source link
Monitor Audio has announced the Creator Series In-Ceiling C2L-A, an angled architectural speaker, which expands its C2L range. The new angled version offers more precise placement and improved performance in custom installed home audio and theater systems.
Architectural audio, specifically in-wall and in-ceiling, has quietly shifted from compromise to a legitimate high-performance category. The reasons are fairly obvious. Sound quality has improved dramatically over the past decade, closing the gap with traditional loudspeakers, while more listeners want superior audio performance without turning their living spaces into showrooms. You can hear it, you just don’t have to look at it. That alone has helped reduce a lot of the domestic pushback that tends to follow large speaker purchases.
The Creator Series itself is Monitor Audio’s fourth-generation architectural lineup, covering both in-wall and in-ceiling designs aimed at custom installation. Within the ceiling category, the range is structured into three performance tiers, giving installers and buyers flexibility depending on room size, budget, and how far down the rabbit hole they want to go.
Monitor Audio Creator Series C2L-A in-ceiling speaker
Three Tiers from Background Audio to High Performance Home Theater
Tier 1: Small, medium, and large models built for cost-effective installs, focusing on straightforward design and dependable acoustic performance.
Advertisement
Two-way configuration
C-CAM mid-bass drivers
C-CAM tweeter with UD Waveguide
Tri-Grip II
Quik-Link
Tier 2: Small, medium, and large in-ceiling models that build on Tier 1 with upgraded acoustic performance and added flexibility, including features like boundary correction and a dual-stereo C2L-T2X option for more versatile placement.
Two-way configuration
RST II mid-bass drivers
C-CAM tweeter with UD Waveguide II
Controlled Performance
Tri-Grip II
Quik-Link
Tier 3: High-performance medium and large in-ceiling models that build on Tier 2 with further acoustic refinement and advanced tuning options, including boundary compensation, mid/high-frequency cut and boost, and more sophisticated driver technologies for greater placement flexibility.
Three-way configuration
RDT III bass drivers
IDC II coaxial mid/tweeter drivers with UD Waveguide II
Controlled Performance
Tri-Grip II
Quik-Link
Pro Tip: Monitor Audio brings angled in-ceiling design down to Tier 2, adding installation flexibility and performance value without stepping up to Tier 3.
Why the C2L-A Is a Smart In-Ceiling Option
The C2L-A is part of the Tier 2 in-ceiling line-up for situations where standard ceiling speakers lose focus. With its angled design, it brings better clarity and direction whether it’s handling height duties in a Dolby Atmos system or anchoring a more precise multi-channel music setup.
The Basics
The C2L-A pairs a 9-inch C-CAM bass-mid driver with RST II cone geometry and a 1.25-inch C-CAM gold dome tweeter. The tweeter is mounted on a central bridge at the acoustic core of the driver and angled at 25 degrees, helping steer high frequencies toward the listening position instead of firing straight down into the carpet.
Acoustic Performance
The C2L-A provides a suite of intelligent installation features and advanced acoustic technologies, including High-frequency (HF) adjustment and boundary compensation. This enables added flexibility in speaker placement, as well as allowing it to be ‘tuned’ to the room to achieve the desired performance. This is optimal for rooms where desired placement might be difficult.
C-CAM
At the core of the C2L-A is a 9-inch C-CAM (Ceramic-Coated Aluminium/Magnesium) driver. It’s light, rigid, and responsive, which translates into lower distortion and cleaner, more detailed sound without adding unnecessary weight or sluggishness.
Advertisement
Advertisement. Scroll to continue reading.
RST II Cone Geometry
This isn’t just cosmetic. The C2L-A uses RST (Rigid Surface Technology) II cone geometry—a hexagonal dimpled structure designed to increase stiffness and control flex across the driver. The goal is straightforward: reduce breakup and distortion so the driver stays more linear under load. In practice, that translates into tighter low-end control, cleaner midrange, and better overall clarity.
Gold Dome Tweeter
A newly designed bridge houses the angled C-CAM 1.25-inch gold dome tweeter, set at a precise 25-degree angle to focus high-frequency energy directly into the desired listening area with precise accuracy.
Installation
Monitor Audio has engineered the C2L-A for easy installation. The speaker features Monitor Audio’s patent-pending Quik-Link speaker cable connector, which supports ease and speed of installation. The Tri-Grip II dog-leg fixings have been re-engineered for a more robust, reliable, and secure fit. The “dog-leg” mechanism allows the C2L-A to be easily secured to plasterboard or dry-lined walls and ceilings.
Advertisement
Design
The C2L-A requires a 248mm (9.76-inch) cut-out, keeping the visual footprint relatively low for its size. It uses near-flush magnetic grilles available in black or white, with an optional square grille for more flexibility in matching room design.
Maximum Peak SPL* (single speaker @ 1m Z-Weighted)
117 dB
Continuous Power Handling (RMS into Nominal Impedance, Pink Noise with 6dB Crest Factor)
120 W
Recommended Amplifier Power (RMS into 8 OHM, Music Signal)
60 – 240 W
Crossover Frequency
LF/HF: 2 kHz
Mounting Depth
99 mm (37/8″)
Cut-Out Hole Diameter
248 mm (93/4″)
External Dimensions (Including Grille (HWD)
278 x 278 x 103 mm 1015/16 x 1015/16 x 44/16 inches
Weight (each)
2.5 kg (5 lb 8 oz)
Pre-Construction Bracket
CL-B
Cabinet Finish
Matte black & Orange & Bronze
Sold As
Single Unit with CL-Round Grille (white)
Corner Switch
On/Off
HF Switch
– /0/ +
Warranty
Lifetime
The Bottom Line
In-wall and in-ceiling speakers aren’t the compromise they used to be, and Monitor Audio clearly understands where the category is headed. The C2L-A stands out because it brings an angled, more directional approach down to a Tier 2 price point, something that used to require stepping into more expensive territory. That matters if you actually care about where the sound lands, not just that it exists somewhere above your head.
That said, this is not a category with a lack of options. Brands like DALI, Focal, Theory Audio Design, KEF, and Q Acoustics are all taking this space seriously, and in some cases, pushing it hard. You still need to treat this like any other speaker purchase because once it’s in the ceiling, it’s not exactly a quick swap.
The C2L-A makes the most sense for listeners building a clean, visually unobtrusive system who still want control over imaging and placement—whether that’s for Dolby Atmos height channels or a more refined multi-room setup. Just don’t wing the install. Cutting holes first and asking questions later is a great way to learn expensive lessons.
Price & Availability
The Monitor Audio Creator C2L-A will be available in September 2026 for $750 USD per piece (£550 / €675) from Authorized Dealers. All Creator Series in-ceiling speakers come with white grilles. For those who want to ‘hide’ or ‘blend’ their integrated speakers with darker décor, black grilles are also available as an optional accessory in round and square designs. For more information, visit: monitoraudio.com.
In a time when almost everything is getting more expensive, this deal on the M5 MacBook Air has me hopeful about how laptop pricing will play out the rest of the year. The M5 MacBook Air has dropped back down to $949, which is $150 off its retail price. It’s only been at this price one other time since the product launched in early March and has more consistently sold for $1,049. As someone who’s reviewed every available MacBook and their strongest competitors, I can unequivocally say that this MacBook Air is one of the very best laptop deals right now.
Apple
MacBook Air (M5, 2026)
Take the Surface Laptop 7th Edition, for example, which has been one of my favorite alternatives to the MacBook Air through all of 2025. It had been at competitive prices with the M4 MacBook Air all along, with both laptops sometimes dropping to as low as $799 during sales events like Prime Day throughout the year. But now, the Surface Laptop has gotten an official price hike due to the RAM shortage and is currently sitting at $1,200. It’s still a laptop I like quite a lot, but at $350 more than a similarly configured M5 MacBook Air, it’s very difficult to recommend.
Advertisement
Or consider the MacBook Neo, Apple’s new budget laptop that also launched in March. While it’s much cheaper overall, it’s only ever been sold for $10 off its full price. At this reduced price for the M5 MacBook Air of $949, that leaves only a dangerously small $260 gap between the Neo and the Air. It’s almost embarrassing how much better the Air is by comparison—in every way imaginable. If you’re curious how these two laptops stack up, I’ve done a comprehensive comparison between them that’s worth checking out. But to put it simply, despite all the excitement (and controversy) around the much cheaper MacBook Neo, the MacBook Air still has the most price flexibility in terms of deals.
Letterboxd has surged in popularity in recent years. Once a niche site for only the most fervent of film nerds, the site — which allows users to rate, review, and recommend movies to one another — has continued to add accounts by the tens of millions, thanks largely to interest from millennials and Gen Z. Now, the company’s controlling investor has apparently made it known that they are looking to cash out.
Semafor reported Sunday that Canadian holding company Tiny, which owns some 60% of Letterboxd, has been courting various potential buyers, including Versant, the parent company of CNBC and MS NOW (formerly MSNBC). Another potential buyer is The Ankler, a popular Hollywood newsletter, according to Semafor. Tiny bought the platform in 2023, valuing it at over $50 million. It’s unclear whether the company has neared any sort of deal.
Representatives for Letterboxd and Tiny did not immediately provide comment when reached by TechCrunch.
Founded in 2011, Letterboxd saw a jump in users in the past few years, climbing to about 26 million users this year, up from 1.7 million in 2020, according to The New York Times. In recent years, the site has seen interest from movie studios, which see it both as a vehicle for marketing films and a source of information about moviegoer trends, as well as from the Oscars, which teamed up with the social platform in a digital content partnership several years ago.
Saros Consulting’s research found that ‘scope creep’ is a significant cause of stress for IT and technical teams.
IT consultancy Saros Consulting has published the results of a new study that explores the issues of stress and mental health among IT employees, as well as the factors that drive them.
In partnership with Censuswide, Saros Consulting collected data from 200 IT decision-makers working out of large, Ireland-based organisations. What was discovered is that three out of every five participating organisations have noticed “stress or mental health issues among IT workers due to intensifying delivery pressures”.
Saros’s research suggests that as more organisations continue to embrace AI, the pressure to roll out new products and systems is creating a fraught working environment for IT and technical teams. Only 58pc of IT leaders admitted that their leadership team has realistic expectations of how AI can benefit them.
Advertisement
Great expectations
Legacy systems were found to be slowing down progress for IT workers, with 59pc of contributors noting that they are running too many, while 57pc explained legacy systems are holding back innovation in their company.
‘Scope creep’ – that is, the continuous or uncontrolled expansion of a person’s work – was also identified as a major issue. Six in 10 participating large organisations reported scope creep as a contributing factor to stress among IT and technical teams, while 61pc also admitted that these teams are working long hours because of talent shortages.
Saros’s research did find, however, that there may be a financial benefit to workers around talent shortages, in that almost 60pc of organisations taking part in the study said they gave an IT or technical team member a 50pc pay increase to discourage them from leaving. According to the report, this underlines the lengths large organisations are willing to go to if it means retaining skilled IT talent.
Fill the gap
A recent report published by the Employment and Recruitment Federation, and supported by Icon Accounting, found that temporary and contract roles are having an impact on the wider working landscape.
Advertisement
Their research found that while Ireland’s jobs market is holding steady, “employer confidence is becoming more measured, with temporary and contract roles now overtaking permanent recruitment in a clear sign of growing caution across the market”.
This change in workplace needs and expectations was also evident in Saros’s data, which found that in order to ease the burden, the outsourcing of IT work is being utilised. Almost one-quarter of IT decision-makers in large organisations said outsourced project management helps reduce stress among technical team members.
Commenting on the findings, Ray Armstrong, the co-founder and co-CEO of Saros Consulting, said, “Our research shows that organisations in Ireland are struggling to address the issue of mental health among IT teams and the leadership team themselves could even be compounding the issue.
“The source of the issue lies in organisations not having a proper IT strategy in place. This means not only coming up with a strategy that is doable, but also one that works in tandem with the business and its goals. Putting a proper plan in place can help to alleviate pressure, provide clarity and lead to happier, more fulfilled workers.”
Advertisement
Justin van der Spuy, also a co-founder and co-CEO of Saros, added, “The sharp rise in cyber threats, coupled with the AI boom and severe staff shortages, have meant that IT teams are under a lot of pressure, to a point where it is becoming too much.
“IT has become the backbone of every organisation; if it ceases to function healthily, then so does the rest of the organisation. IT leaders must look holistically at how they can support their teams. Pay rises alone can’t cure sleep deprivation.”
AI – and ensuring that organisations are fully prepared to embrace future skills and security needs – is an important topic for most organisations in 2026.
In response, the Irish Government recently launched AIReady.ie, a new national AI skilling platform designed to provide people across Ireland with the means to learn essential AI skills.
Advertisement
Developed by Solas, in partnership with the National Skills Council, the programme will aim to teach the fundamentals of AI, with a curriculum designed to support people as they work to develop the in‑demand skills needed for work, study and everyday life.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
Govee, a leading smart light maker, on Monday launched what could be the most interesting ceiling light we’ve seen. The Govee Ceiling Light Ultra turns your entire ceiling into a glowing array of light, complete with AI-generated scenes.
The 21-inch disk-shaped overhead light is filled with over 600 ultradense LEDs, featuring a screen-grade matrix layout, allowing you to do some very cool things with this light. The launch video shows an artist taking a photo of their painting of the Mona Lisa and then sending it directly to the light for display. It’s not digital picture frame quality, but you get the idea.
The light also casts a wide array of light around the ceiling, showing off the power of that many LEDs and making it easy to set the right mood. And while the colorful effects may be the show stealer, you can also have the light follow sunrise and sunset times and adjust in real time. This isn’t a new feature for smart lights, but it’ll likely have a greater impact here given how large and bright this ceiling light is.
Advertisement
Since it’s 2026, you can also expect a healthy serving of AI with the light. Owners can create a colorful lighting scene with an AI prompt. The Ceiling Light Ultra also comes with more than 100 lighting effects and music-sync modes, so you can set the vibe just the way you like it.
Govee makes some of the best smart lighting solutions around, but it’s far from the only player. Philips Hue lights are largely considered superior, but cost significantly more. The Govee Ceiling Light Ultra will run you $250, which, in the grand scheme of things, isn’t a terrible deal for what you get. Now, factor in that Philips Hue has no comparable type of lighting solution, and Govee might have a winner on its hands.
You can buy the Ceiling Light Ultra from Govee direct or at Amazon, with a shipping estimate of May 2.
All HDMI cables support high-definition outputs, but not all can actually support full 4K resolutions. If you want to make the most of your 4K TV or monitor, you’ll need to make sure you have the right HDMI cable to set it up. Otherwise, you’ll find yourself stuck at a lower resolution regardless of the visual quality of what you’re trying to watch or play.
It’s not always immediately obvious what your HDMI cable is capable of. However, there are a few things to know, and a couple of things that you can look out for to help you get to the bottom of things. For starters, you can check which generation your HDMI cable belongs to. HDMI cables can only output at 4K if they’re from generation 1.4 or later. Your best bet for checking this is your cable’s packaging or any proof of purchase, which will typically label exactly which generation your HDMI cable belongs to. Look out for cables labeled with 1.4 or above, and especially for HDMI cables labeled with 2.0 or 2.1.
Don’t despair if you don’t have the packaging or proof of purchase lying around. If you look closely at the cable itself, most reputable brands print the speed rating directly on the rubber jacket. To get 4K output, look for cables with the words ‘High Speed’ (which aligns with HDMI 1.4 capabilities), ‘Premium High Speed’ (HDMI 2.0), or ‘Ultra High Speed’ (HDMI 2.1) printed along the wire. Or, if you bought your HDMI cable at any point since 2009 and it wasn’t secondhand, there’s a very good chance it can output up to 4K resolution when connected to the right device since HDMI 1.4 launched around then.
Advertisement
Which HDMI generations work best for outputting 4K?
Monticelllo/Getty Images
You could easily assume that all HDMI cables and ports are created roughly equally. After all, they all have broadly the same purposes: to transmit video and audio information. However, it’s not that simple. Since HDMI launched back in 2002, it has received a long list of specification updates that have tweaked the connection and cable capabilities to allow for higher definitions, faster frame rates, and new features.
Choosing the right HDMI cable for your 4K TV or monitor is important for achieving the best experience possible, and one way to do that is by being selective about which generation of cable you use. HDMI generations are linear, meaning the newer the generation — and in turn, the higher the number associated with it — the better quality the image is. So, it’s a good rule of thumb when buying a new HDMI cable to grab the newest generation option available to you.
Advertisement
Even though 1.4 can output at 4K, it’s worth looking for a 2.0 or 2.1 HDMI cable if possible, as they can support higher refresh rates at 4K than their predecessors can. HDMI 2.0 cables support 4K at 60 Hz, while 2.1 cables can output 4K at 120 Hz, assuming your device supports it. Meanwhile, 1.4 cables can only output 4K at 30 Hz for standard UHD TVs. Higher frame rates can make videos look smoother by showing more images per second, in turn improving the overall picture quality and helping your 4K visuals shine.
A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 “sleeper” extensions that turn malicious after an update.
Six of the extensions have been activated and deliver malware, while researchers assess with high confidence that the rest of them are dormant or at least suspicious.
When initially uploaded, the extensions are benign but deliver the payload at a later stage, revealing the attacker’s true intention.
“This count may change as new updates continue to appear, but the pattern is consistent with earlier GlassWorm waves,” say researchers at application security company Socket.
GlassWorm is an ongoing supply chain attack campaign first observed in October, initially using invisible Unicode characters to hide malicious code that steals cryptocurrency wallets and developer credentials.
A recent wave in mid-March 2026 showed significant scale, affecting hundreds of repositories and dozens of extensions.
However, operations of such a scale can be noisy and leave multiple traces, as multiple distinct research teams caught the activity early and helped block it.
The latest wave suggests that the attacker’s intent is to change their strategy by submitting innocuous extensions to a single ecosystem and introducing the malicious payload in a subsequent update, rather than embedding it in the extensions.
Advertisement
Socket has found that the 73 extensions involved in the most recent GlassWorm campaign are clones of legitimate listings, designed to trick developers who do not pay much attention beyond visuals.
In one case, the attacker used the same icon as the legitimate extension, adopted a similar naming and description. Although there are subtle differences, the main indicators are the name of the publisher and the unique identifier.
Instead of carrying the malware, the extensions now act as thin loaders that fetch it via one of the following methods:
The extension retrieves a secondary VSIX package from GitHub at runtime and installs it using CLI commands.
The extensions load platform-specific compiled modules (.node files) that contain the core logic, including fetching additional payloads and executing installation routines across supported editors.
Some variants rely entirely on heavily obfuscated JavaScript that decodes at runtime to fetch and install malicious extensions, sometimes including encrypted or fallback URLs for payload retrieval.
Socket did not provide technical details about the newest payload. Previously, these attacks were aimed at stealing cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment data.
The cybersecurity company has published the full list of the 73 extensions believed to be part of the latest GlassWorm wave. Developers who installed any of them are recommended to rotate all secrets and clean their environment.
Advertisement
AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.
At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.
You must be logged in to post a comment Login