GlassWorm Uses Zig Dropper to Infect Developer IDEs

Why it matters: The GlassWorm campaign's new Zig dropper directly compromises developer IDEs, increasing software supply chain risks.
- GlassWorm campaign now uses a new Zig dropper to infect developer IDEs.
- Zig dropper is designed to stealthily compromise all integrated development environments on a developer's machine.
- Open VSX extension was found to contain this new infection technique.
The GlassWorm campaign has evolved, now utilizing a new Zig dropper to infect multiple developer IDEs on a machine. This stealthy technique was identified within an Open VSX extension, posing a significant threat to developers.




