A stealthy new iteration of the GlassWorm campaign is infiltrating developer environments by weaponizing a counterfeit Visual Studio Code extension that deploys a Zig-compiled dropper capable of silently contaminating every compatible IDE on an infected machine, Security Affairs reports.According to researchers at Aikido, the attack hinges on a malicious OpenVSX package impersonating the legitimate WakaTime productivity tracker, which loads a native binary operating entirely outside the restrictive JavaScript sandbox with unfettered system access. Rather than delivering an immediate payload, this binary methodically scans for installations of VS Code, Cursor, and VSCodium before injecting a secondary GlassWorm dropper disguised as a benign plugin across all detected tools."This is not the first time GlassWorm resorted to using native compiled code," the Aikido report notes, highlighting the group's continuous adaptation beyond its earlier reliance on poisoned npm packages. The malware deliberately avoids execution on Russian systems and maintains communication via a Solana blockchain-based command-and-control infrastructure. Once entrenched, the second-stage implant exfiltrates sensitive data and establishes persistent remote access through a rogue Chrome extension, necessitating a full credential rotation and system remediation upon discovery of indicators like floktokbok.autoimport.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




