logo

GlassWorm Trojan Hits VS Code, Cursor, Windsurf via OpenVSX Extension

ID: 9b775a11-6f42-5bec-b6a8-4cb18d77ae67

STIX ID: report--9b775a11-6f42-5bec-b6a8-4cb18d77ae67

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A supply-chain campaign tracked as GlassWorm is infecting developer environments by trojanizing OpenVSX/VS Code extensions and npm packages. A malicious extension impersonating WakaTime activates a bundled native Zig binary (Node.js native addon) that scans for IDEs, downloads a malicious .vsix from attacker-controlled GitHub Releases, and silently installs it across editors. The second-stage payload connects to a Solana-based C2 and can deploy RATs and browser-based credential theft; the campaign has been observed since March 2025 and includes region-based exclusion logic. Recommended actions include removing suspicious extensions, rotating keys/credentials, scanning for persistence, and monitoring outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.