logo

GlassWorm goes native: New Zig dropper infects every IDE on your machine

ID: 3662a25d-e339-5c71-8e2b-5d281ba6f2fc

STIX ID: report--3662a25d-e339-5c71-8e2b-5d281ba6f2fc

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-04-08

Date Updated: 2026-07-24

...
...

**Executive summary:** The GlassWorm campaign trojanized an OpenVSX extension (specstudio/code-wakatime-activity-tracker) that ships Zig-compiled native Node addons (win.node, mac.node) which execute outside the JavaScript sandbox to discover IDEs and silently install a malicious VSIX (autoimport-2.7.9) across VS Code-compatible editors; the second-stage implant is a known GlassWorm dropper that geofences Russian systems, beacons to a Solana-based C2, performs secret exfiltration, and installs a persistent RAT — IOCs include extension names, two binary SHA-256 hashes, and a GitHub Releases URL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.