GlassWorm Targets Developer IDEs Again, Hiding Staged Malware Behind Runtime-Rebuilt Loaders
ID: e3e6921c-cc1c-5121-b286-0776c005cc3d
STIX ID: report--e3e6921c-cc1c-5121-b286-0776c005cc3d
Feed Name: Checkmarx Zero
Checkmarx Zero describes a GlassWorm campaign distributing malicious VS Code/Open VSX extensions (13 packages, ~50k downloads) that use obfuscated loaders and Solana memos for staged payload delivery. The malware harvests developer credentials (npm, GitHub), targets cryptocurrency wallets, establishes persistence and remote access (HVNC, SOCKS, DHT/socket communications), performs regional (Russian) evasion, and provides extensive IoCs (RPC endpoints, wallet addresses, IPs, file and registry artifacts) for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
