logo

Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf

ID: 2df96f7a-182b-5729-bf3c-9f73b8471bfc

STIX ID: report--2df96f7a-182b-5729-bf3c-9f73b8471bfc

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious OpenVSX extension published as specstudio/code-wakatime-activity-tracker contains Zig-compiled native binaries (win.node, mac.node) that load into Node.js, download a second-stage VSIX (autoimport-2.7.9 resembling steoates.autoimport), and silently install it across all IDEs supporting the VS Code extension format. The GlassWorm dropper, previously seen embedding payloads in npm packages, now uses native binaries to gain full OS access, beacons to a Solana-based C2, avoids Russian locales, exfiltrates data, and deploys a persistent RAT plus a malicious Chrome extension; affected machines should be treated as fully compromised and secrets rotated immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.