Aikido Security has uncovered a new GlassWorm campaign using a fake WakaTime extension on OpenVSX that bundles a Zig-compiled native Node.js addon. Once loaded, the binary silently scans the developer's machine for all VS Code-compatible IDEs (VS Code, Cursor, Windsurf, VSCodium, Positron) and force-installs a malicious .vsix
Table of contents
The dropper: a trojanized extensionInfecting every IDE on the machineThe Second-Stage ExtensionIOCs5 Comments
Sort: