Glassworm Malware Infects Popular React Native npm Packages
ID: 0bdc780a-a2bc-5ad4-a69c-c4574defdd2f
STIX ID: report--0bdc780a-a2bc-5ad4-a69c-c4574defdd2f
Feed Name: GBHackers
A March 16, 2026 supply-chain compromise of two AstrOOnauta npm packages introduced an obfuscated install.js run via npm preinstall hooks, delivering a multi-stage Glassworm-linked loader. The chain used a Solana transaction memo to retrieve a base64 link and AES-encrypted stages, ultimately deploying a Windows credential-and-wallet stealer that establishes persistence, downloads a full Node.js runtime, harvests browser wallets/extensions and developer credentials, and exfiltrates data to 45.32.150.251 and 217.69.3.152.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
