logo

Glassworm Malware Infects Popular React Native npm Packages

ID: 0bdc780a-a2bc-5ad4-a69c-c4574defdd2f

STIX ID: report--0bdc780a-a2bc-5ad4-a69c-c4574defdd2f

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A March 16, 2026 supply-chain compromise of two AstrOOnauta npm packages introduced an obfuscated install.js run via npm preinstall hooks, delivering a multi-stage Glassworm-linked loader. The chain used a Solana transaction memo to retrieve a base64 link and AES-encrypted stages, ultimately deploying a Windows credential-and-wallet stealer that establishes persistence, downloads a full Node.js runtime, harvests browser wallets/extensions and developer credentials, and exfiltrates data to 45.32.150.251 and 217.69.3.152.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.