GlassWorm attack installs fake browser extension for surveillance
ID: 32521299-f8a7-5705-8eaa-4aa140f30c79
STIX ID: report--32521299-f8a7-5705-8eaa-4aa140f30c79
Feed Name: Malwarebytes Blog
GlassWorm is a multi-stage supply-chain malware campaign targeting developers via malicious or compromised packages and extensions (npm, PyPI, VS Code). It uses preinstall scripts and invisible loaders to fingerprint hosts (skipping Russian locales), retrieves stage-two payload info from the Solana blockchain memo field, deploys an infostealer to harvest wallets, credentials, and tokens, then installs a Node.js RAT and Ledger/Trezor phishing binaries; it persists via startup entries and scheduled tasks, uses DHT and blockchain-based C2 resolution, and force-installs a malicious Chrome extension to capture DOM, cookies, keystrokes and more. IOCs in the report include multiple IPs, registry Run keys, a scheduled task (AghzgY.ps1), and a fake "Google Docs Offline" extension.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
