logo

Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet

ID: 35449478-dc20-5320-b80c-c165a4847cd0

STIX ID: report--35449478-dc20-5320-b80c-c165a4847cd0

Feed Name: Crowdstrike Blog

Threat Score
88/100

Date Published: 2026-05-26

Date Updated: 2026-05-27

Author: Counter Adversary Operations

...
...

CrowdStrike describes a coordinated takedown of “Glassworm,” a sophisticated supply-chain focused botnet that targeted software developers by distributing trojanized VSCode extensions, malicious npm/PyPI packages, and poisoned GitHub repositories to deliver a Node.js RAT and credential-stealing components; the report details resilient C2 mechanisms (Solana memo fields, BitTorrent DHT, Google Calendar dead-drops, and direct servers), shares an IOC (beacon IP 164.92.88.210) and YARA rules, and emphasizes the broad, high-impact risk to developer ecosystems and dependent organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.