logo

An Evolving GlassWorm Malware is Making the Rounds of Code Repositories

ID: 7be5383d-651e-5068-ae8d-26f8d7416d0e

STIX ID: report--7be5383d-651e-5068-ae8d-26f8d7416d0e

Feed Name: Security Boulevard

Threat Score
78/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

GlassWorm, a persistent supply-chain malware actor, has resurged with an evolved multi-stage framework that distributes malicious packages and extensions across npm, PyPI, Open VSX, GitHub and Visual Studio Marketplace to harvest credentials, exfiltrate cloud secrets and crypto, and install a RAT with HVNC capabilities; it uses invisible Unicode loaders, Solana memo-based C2, transitive extension dependencies for stealthy delivery, and has begun compromising MCP servers used by AI tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.