GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data
ID: 1ba6ca14-6742-5c33-9b98-7b3c807a175f
STIX ID: report--1ba6ca14-6742-5c33-9b98-7b3c807a175f
Feed Name: The Hacker News
Researchers uncovered a sophisticated GlassWorm supply-chain campaign that pushes poisoned packages across npm, PyPI, GitHub and Open VSX to deploy a multi-stage data-theft framework and RAT; components include a .NET hardware-wallet phishing module, a WebSocket/JavaScript RAT that force-installs a malicious Google Docs Offline Chrome extension to harvest cookies, DOM, keystrokes and more, and use Solana transactions and DHT as dead-drop C2 resolvers, with multiple external IPs and endpoints observed for exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
