Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GlassWorm Malware Disrupted in Major Supply Chain Attack

GlassWorm Malware Disrupted in Major Supply Chain Attack

Posted on May 27, 2026 By CWS

CrowdStrike, alongside Google and the Shadowserver Foundation, has executed a strategic takedown of the command-and-control (C2) channels linked to GlassWorm, a malware campaign that has been targeting software developers through deceptive packages and extensions. This collective action has effectively disrupted the infrastructure supporting this persistent threat.

Targeting Software Developers

Since early 2025, the operators of GlassWorm have systematically attacked software developers, exploiting their access to source code repositories, cloud services, and CI/CD pipelines. This development highlights the growing threat of software supply chain attacks, where a single compromised developer workstation can have widespread repercussions across numerous organizations and users.

GlassWorm’s tactics involved deploying Trojan-laden VS Code extensions on platforms like Microsoft VS Code Marketplace and Open VSX. This enabled them to target users of various VS Code forks, including Cursor, Positron, Windsurf, and VSCodium. Additionally, the campaign infiltrated npm and Python packages, aiming to deliver a data-stealing framework capable of harvesting credentials, cryptocurrency wallets, and profiling systems.

Advanced Malware Techniques

In its evolution, GlassWorm introduced a Websocket-based JavaScript RAT, known as GlassWormRAT, to extract web browser data and execute arbitrary code. One method involved installing a Google Chrome extension to gather sensitive information such as screenshots, keystrokes, and clipboard data from compromised systems.

According to Endor Labs researcher Kiran Raj, the malware actively searches for developer credentials to facilitate further breaches of repositories and package uploads. Infected machines are then converted into covert infrastructures, such as SOCKS proxies and hidden VNC servers, providing attackers with anonymized network access and a platform for further attacks.

Impact and Ongoing Risks

The malicious operations are estimated to have compromised over 300 GitHub repositories using stolen credentials. Notably, GlassWorm utilized four different C2 channels to enhance its resilience against takedowns, integrating blockchain, peer-to-peer, and legitimate web services to obscure the actual C2 servers.

This coordinated takedown has neutralized all four channels, preventing further instructions or payloads from reaching infected systems. Despite this success, the threat posed by well-resourced operators, likely based in Russia, remains significant, as their malware avoids execution in systems within the Commonwealth of Independent States (CIS) regions and contains Russian language comments.

CrowdStrike emphasizes the critical nature of the software supply chain as a target for cyber adversaries. The ease of compromising a package or extension poses a substantial risk, with the potential for widespread impact. As developer environments and build pipelines remain vulnerable, organizations consuming software inherit the risks of those producing it. The GlassWorm campaign underscores the need for robust protections to prevent persistent threats to developer ecosystems.

The Hacker News Tags:C2 channels, CrowdStrike, Cybercrime, Cybersecurity, data theft, developer security, GlassWorm, infrastructure takedown, Malware, NPM, Python packages, Russia-based threat, software developers, supply chain attack, VS Code

Post navigation

Previous Post: Link11 Launches Technical Hub in Lisbon for Enhanced Security
Next Post: Join AI Risk Summit 2026 at Ritz-Carlton, Half Moon Bay

Related Posts

Malicious Ruby and Go Modules Target CI Environments Malicious Ruby and Go Modules Target CI Environments The Hacker News
Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers The Hacker News
The Wild West of Shadow IT The Wild West of Shadow IT The Hacker News
AI Advances in Cybersecurity Pose New Challenges AI Advances in Cybersecurity Pose New Challenges The Hacker News
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access The Hacker News
OpenAI Enhances AI Security Amid Training Pause OpenAI Enhances AI Security Amid Training Pause The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Next.js Flaws Allow Remote Code Execution
  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal
  • Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Next.js Flaws Allow Remote Code Execution
  • Ubiquiti Patches 21 Critical UniFi Vulnerabilities
  • Google Chrome 152 Launches with Key Security Fixes
  • Iranian Hacking Group Enhances Malware Arsenal
  • Mirage2FA Bypasses MFA, Compromises Microsoft 365 Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark