Threat Intelligence, DevOps

GlassWorm uses Zig binary to infect multiple IDEs

Cybersecurity threat concept with hands typing on laptop and warning symbols floating in digital space.

A stealthy new iteration of the GlassWorm campaign is infiltrating developer environments by weaponizing a counterfeit Visual Studio Code extension that deploys a Zig-compiled dropper capable of silently contaminating every compatible IDE on an infected machine, Security Affairs reports.

According to researchers at Aikido, the attack hinges on a malicious OpenVSX package impersonating the legitimate WakaTime productivity tracker, which loads a native binary operating entirely outside the restrictive JavaScript sandbox with unfettered system access. Rather than delivering an immediate payload, this binary methodically scans for installations of VS Code, Cursor, and VSCodium before injecting a secondary GlassWorm dropper disguised as a benign plugin across all detected tools.

"This is not the first time GlassWorm resorted to using native compiled code," the Aikido report notes, highlighting the group's continuous adaptation beyond its earlier reliance on poisoned npm packages. The malware deliberately avoids execution on Russian systems and maintains communication via a Solana blockchain-based command-and-control infrastructure. Once entrenched, the second-stage implant exfiltrates sensitive data and establishes persistent remote access through a rogue Chrome extension, necessitating a full credential rotation and system remediation upon discovery of indicators like floktokbok.autoimport.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds