GlassWorm's Zig Dropper Hijacks Every IDE on Dev Machines
Cyber crooks just upped their game in the GlassWorm campaign, slipping a Zig dropper into a phony WakaTime tracker that chains infections across all your IDEs. It's not just VS Code—think Cursor, VSCodium, the works.
theAIcatchupApr 10, 20264 min read
⚡ Key Takeaways
GlassWorm's Zig dropper infects multiple IDEs like VS Code, Cursor, and VSCodium from one fake extension.𝕏
Uses indirection via native binaries to evade sandboxes and spread silently via CLI installers.𝕏
Targets high-value devs for creds, code access; rotate secrets if exposed.𝕏
The 60-Second TL;DR
GlassWorm's Zig dropper infects multiple IDEs like VS Code, Cursor, and VSCodium from one fake extension.
Uses indirection via native binaries to evade sandboxes and spread silently via CLI installers.
Targets high-value devs for creds, code access; rotate secrets if exposed.