Glassworm botnet disrupted after resilient C2 infrastructure takedown
The Glassworm botnet, a supply-chain threat targeting developers, has been significantly disrupted following a coordinated takedown of its resilient command-and-control infrastructure. The botnet utilized a complex architecture incorporating blockchain, BitTorrent, and public calendar services to evade traditional disruption methods. This disruption highlights the evolving tactics employed by sophisticated threat actors and the need for robust supply-chain security measures.
Glassworm, initially launched in October 2025, has been targeting software developers through malicious extensions for OpenVSX and Microsoft VS Code, primarily to steal cryptocurrency wallets and credentials. The botnet’s sophistication was demonstrated by its expansion to compromise GitHub repositories and npm packages, with a notable campaign in March impacting over 400 software artifacts. A particularly concerning tactic involved planting dormant extensions on OpenVSX that activated upon updates, further complicating detection and remediation efforts. The botnet’s resilience stemmed from its multi-layered C2 infrastructure, utilizing unconventional channels like Solana blockchain transactions, the BitTorrent DHT network, and Google Calendar events to avoid takedowns.