GlassWorm Trojan Hits VS Code, Cursor, Windsurf via OpenVSX Extension
ID: 9b775a11-6f42-5bec-b6a8-4cb18d77ae67
STIX ID: report--9b775a11-6f42-5bec-b6a8-4cb18d77ae67
Feed Name: GBHackers
A supply-chain campaign tracked as GlassWorm is infecting developer environments by trojanizing OpenVSX/VS Code extensions and npm packages. A malicious extension impersonating WakaTime activates a bundled native Zig binary (Node.js native addon) that scans for IDEs, downloads a malicious .vsix from attacker-controlled GitHub Releases, and silently installs it across editors. The second-stage payload connects to a Solana-based C2 and can deploy RATs and browser-based credential theft; the campaign has been observed since March 2025 and includes region-based exclusion logic. Recommended actions include removing suspicious extensions, rotating keys/credentials, scanning for persistence, and monitoring outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
