logo

CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain

ID: 24125e05-533a-5f17-aa42-20e9a4085058

STIX ID: report--24125e05-533a-5f17-aa42-20e9a4085058

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Greg Otto

...
...

CrowdStrike, with assistance from Google and Shadowserver, dismantled the Glassworm botnet that had been infecting open-source packages and developer workflows since early 2025. The group pushed malware (including GlasswormRAT) into VSCode extensions, npm/Python packages and 300+ GitHub repositories, targeting developers to harvest credentials and source code across Windows, macOS and Linux; defenders disrupted four attacker servers and disrupted layered propagation channels (Solana blockchain, BitTorrent, Google Calendar, and commercial VPS), and shared IOCs to help organizations hunt for infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.