logo

GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX

ID: 52206ae8-5dc3-5f43-925d-22bc5195eba5

STIX ID: report--52206ae8-5dc3-5f43-925d-22bc5195eba5

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-03-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GlassWorm is a large-scale supply-chain campaign that has compromised 433 open-source components (200 Python GitHub repos, 151 JS/TS repos, 72 VSCode/OpenVSX extensions, and 10 npm packages) by abusing compromised GitHub accounts to push malicious commits and publishing trojanized packages. The attackers use invisible Unicode obfuscation, poll a Solana blockchain address for C2 memos (50 transactions observed between Nov 27, 2025 and Mar 13, 2026) to update payload URLs, and deploy a JavaScript infostealer targeting crypto wallets, credentials, SSH keys, and developer environment data; notable indicators include the marker variable "lzcdrtfxyqiplpd", a ~/init.json persistence file, and unexpected Node.js installs in home directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.