news.mlab.sh
Back to the feed
threat-intel

GlassWorm Botnet Disrupted

High
Summary

The GlassWorm botnet, a persistent threat targeting open-source software developers, has been disrupted by a coordinated effort between CrowdStrike, Google, and the Shadowserver Foundation. The botnet utilized a multi-layered C&C infrastructure including blockchain, BitTorrent, and traditional VPS providers to evade takedowns and steal sensitive credentials. This disruption highlights a broader trend of attackers targeting developer ecosystems and underscores the importance of robust security measures across the software supply chain.

The GlassWorm botnet, initially spotted in October 2025, has been a significant threat to open-source software development for over a year. It operated by distributing trojanized Visual Studio extensions via the OpenVSX marketplace and later emerged on GitHub, targeting VS developers and expanding across package ecosystems like VSCode, npm, PyPI, and GitHub. The botnet’s sophisticated architecture involved utilizing Solana blockchain for C&C, Google Calendar for storing encoded paths, and BitTorrent for configuration data, creating a resilient network designed to withstand takedowns. GlassWorm’s operators were adept at adapting, employing diverse programming languages (JavaScript, Rust, Zig) and building redundant infrastructure to avoid detection and disruption.

The malware’s primary objective was to steal sensitive information, including NPM, GitHub, and Git credentials, and funds from cryptocurrency extensions. It also deployed SOCKS proxy servers and hidden VNC servers for remote access. This created a significant risk of supply chain compromises, impacting not only developers but also any organizations consuming the potentially affected software. Evidence suggests the operators are of Russian origin, based on the malware’s locale checks and Russian-language comments within the code. This disruption is a critical moment, signaling a shift in the threat landscape where attackers are proactively targeting developer ecosystems to maintain persistent access.

CrowdStrike has advised organizations to monitor for connections to the IP address 164.92.88[.]210 to identify potential infections. The takedown underscores the need for organizations to prioritize security across their entire software supply chain, recognizing that vulnerabilities in developer environments can have far-reaching consequences.

Read the full article at SecurityWeek