Cybersecurity Alert: New GlassWorm Malware Targets Developers
Cybersecurity experts have identified a concerning evolution of the GlassWorm malware campaign, which now utilizes a deceptive extension named “specstudio.code-wakatime-activity-tracker.” This malicious software is designed to infiltrate various integrated development environments (IDEs) on developers’ machines.
The attack primarily affects developers using Microsoft Visual Studio Code and its forks, as the malware silently installs itself and pulls additional harmful extensions from an attacker-controlled GitHub account. Users of the compromised extension are at significant risk, as the malware can steal sensitive data and install remote access trojans.
To protect against this threat, developers should immediately uninstall the malicious extension and rotate any sensitive credentials. Regularly updating software and using trusted sources for extensions can also help mitigate the risk.
Risk Level: High
Stay vigilant and ensure your development environment is secure.
Source: View Original Report
