logo

GlassWorm Targets Developer IDEs Again, Hiding Staged Malware Behind Runtime-Rebuilt Loaders

ID: e3e6921c-cc1c-5121-b286-0776c005cc3d

STIX ID: report--e3e6921c-cc1c-5121-b286-0776c005cc3d

Feed Name: Checkmarx Zero

Threat Score
80/100

Date Published: 2026-03-23

Date Updated: 2026-05-12

Author: Daniel Miranda

...
...

Checkmarx Zero describes a GlassWorm campaign distributing malicious VS Code/Open VSX extensions (13 packages, ~50k downloads) that use obfuscated loaders and Solana memos for staged payload delivery. The malware harvests developer credentials (npm, GitHub), targets cryptocurrency wallets, establishes persistence and remote access (HVNC, SOCKS, DHT/socket communications), performs regional (Russian) evasion, and provides extensive IoCs (RPC endpoints, wallet addresses, IPs, file and registry artifacts) for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.