AUTO-UPDATED

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

CrowdStrike, Google, and the Shadowserver Foundation have successfully neutralized the GlassWorm campaign, a sophisticated operation that targeted software developers by distributing malicious extensions and packages to steal sensitive credentials.

Key Points

  • GlassWorm operators targeted developers via trojanized VS Code extensions and compromised npm and Python packages to exfiltrate data and cryptocurrency.
  • The malware utilized four resilient command-and-control channels, including the Solana blockchain, BitTorrent DHT, and Google Calendar, to evade detection.
  • The campaign successfully poisoned over 300 GitHub repositories, using infected workstations as proxies for further network infiltration.
  • CrowdStrike attributes the activity to Russia-based cybercriminals, noting the malware avoids systems located within Commonwealth of Independent States countries.
  • The coordinated takedown simultaneously disabled all four command-and-control layers, preventing infected machines from receiving further instructions or malicious payloads.

Why it Matters

  • This operation highlights the growing trend of supply chain attacks that leverage developer environments to gain unauthorized access to corporate infrastructure. By compromising a single workstation, attackers can potentially impact thousands of downstream users and organizations, making developer security a critical priority for modern cybersecurity.
Internet Published by info@thehackernews.com (The Hacker News)
Read original