logo

GlassWorm Hides a RAT Inside a Malicious Chrome Extension

ID: 28f60f77-d89c-5593-9963-9be01238228a

STIX ID: report--28f60f77-d89c-5593-9963-9be01238228a

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-03-18

Date Updated: 2026-07-24

...
...

**Executive Summary:** The report analyzes 'GlassWorm', a sophisticated supply-chain malware campaign that delivers a multi-stage information-stealing framework via compromised npm/PyPI/GitHub/VSX packages; it uses Solana memos and DHT lookups for resilient C2, exfiltrates developer/cloud/crypto credentials and session tokens, force-installs a malicious Chrome extension posing as Google Docs Offline, and maintains robust persistence and remote control capabilities—extensive IOCs (IPs, URLs, wallet addresses, hashes, file paths, registry keys) are provided to support detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.