A fake developer extension on the OpenVSX marketplace is spreading the GlassWorm malware to multiple code editors, including VS Code and Cursor. This sophisticated attack uses native binaries to infect all compatible IDEs silently, installing a malicious second-stage extension that exfiltrates data and installs a Remote Access Trojan. Developers must urgently check their extensions for signs of compromise and rotate credentials accordingly.
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



