Analysis of GlassWorm V2 Malware via Compromised Cursor Extension

Analysis of GlassWorm V2 Malware via Compromised Cursor Extension

First seen 13 Mar 2026, 08:13 UTC Reddit 72% similarity 66.5

Article Content

Browse articles
ThreatCluster

A variant of the GlassWorm malware has been identified, distributed through a compromised Cursor extension on Open VSX. The attack utilizes a sophisticated infection chain and a resilient command-and-control (C2) architecture designed to withstand takedowns. Over a 57-hour monitoring period, ongoing operator activity was observed, indicating active exploitation. The malware's persistence mechanism allows it to maintain control over infected systems. The exact number of affected users is currently unknown, but the implications for software supply chain security are significant. The presence of an 'interesting' kill switch suggests a level of sophistication in the malware's design. Security professionals are urged to monitor for signs of this variant in their environments. Further technical details, including specific indicators of compromise (IOCs), are pending publication.

Key Points: • GlassWorm V2 is distributed via a compromised Cursor extension on Open VSX. • The malware features a resilient C2 architecture and a sophisticated infection chain. • Ongoing operator activity was observed over a 57-hour monitoring period.

ThreatCluster AI

Timeline

2026-03-13
GlassWorm V2 analysis published on Reddit
Date unknown
Compromise of Cursor extension confirmed
Date unknown
Monitoring of operator activity initiated

Community

Browse all →