Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf
ID: 2df96f7a-182b-5729-bf3c-9f73b8471bfc
STIX ID: report--2df96f7a-182b-5729-bf3c-9f73b8471bfc
Feed Name: cybersecurityNews.com
A malicious OpenVSX extension published as specstudio/code-wakatime-activity-tracker contains Zig-compiled native binaries (win.node, mac.node) that load into Node.js, download a second-stage VSIX (autoimport-2.7.9 resembling steoates.autoimport), and silently install it across all IDEs supporting the VS Code extension format. The GlassWorm dropper, previously seen embedding payloads in npm packages, now uses native binaries to gain full OS access, beacons to a Solana-based C2, avoids Russian locales, exfiltrates data, and deploys a persistent RAT plus a malicious Chrome extension; affected machines should be treated as fully compromised and secrets rotated immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
