Aikido Security has uncovered a new GlassWorm campaign using a fake WakaTime extension on OpenVSX that bundles a Zig-compiled native Node.js addon. Once loaded, the binary silently scans the developer's machine for all VS Code-compatible IDEs (VS Code, Cursor, Windsurf, VSCodium, Positron) and force-installs a malicious .vsix

4m read timeFrom aikido.dev
Post cover image
Table of contents
The dropper: a trojanized extensionInfecting every IDE on the machineThe Second-Stage ExtensionIOCs
5 Comments

Sort: