logo

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

ID: 173a1591-d36a-5fa5-a1a3-19c7bdf2ab79

STIX ID: report--173a1591-d36a-5fa5-a1a3-19c7bdf2ab79

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: [email protected] (The Hacker News)

...
...

CrowdStrike, in partnership with Google and the Shadowserver Foundation, disrupted all command-and-control channels for GlassWorm, a developer-focused supply-chain campaign (active since at least early 2025) that used trojanized VS Code extensions and compromised npm/Python packages to deploy the GlassWormRAT data-stealer, harvest developer credentials and crypto wallets, and convert infected hosts into proxies, HVNC servers, and remote execution nodes; the campaign reportedly poisoned over 300 GitHub repositories and is attributed to likely Russia-based cybercriminals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.