Switch language한국어
Back to the list

CrowdStrike takes down Glassworm botnet

TL;DR AI

Key summary

2 min read
  1. CrowdStrike, with Google and Shadowserver Foundation, disrupted Glassworm, a botnet that has targeted developers since early 2025.

  2. Glassworm spread through malicious extensions, infected packages, and stolen accounts across OpenVSX, GitHub, npm, and PyPI.

  3. The campaign hit more than 300 GitHub repositories and used unusual C2 channels, including Solana transactions, BitTorrent DHT, Google Calendar, and VPS servers.

  4. The malware enabled credential theft, data exfiltration, remote access, and proxy abuse, underscoring a growing software supply-chain threat.

Read the original