GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
ID: edce38bf-66b4-56f6-9bde-d6bc1766b0df
STIX ID: report--edce38bf-66b4-56f6-9bde-d6bc1766b0df
Feed Name: The Hacker News
Cybersecurity researchers uncovered a GlassWorm campaign using a malicious VS Code extension impersonating WakaTime that includes a Zig-compiled native Node addon; the addon locates IDEs, downloads and silently installs a second-stage malicious VSIX across multiple editors, fetches command-and-control via the Solana blockchain, deploys a RAT and a Chrome information-stealing extension, and exfiltrates sensitive data — users of the affected extensions should assume compromise and rotate secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
