GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
CrowdStrike, in collaboration with Google and Shadowserver Foundation, successfully disrupted the command-and-control infrastructure of the GlassWorm malware campaign, which targeted software developers through compromised VS Code extensions and package registries. The operation involved a multi-layered C2 strategy, including blockchain, BitTorrent, and Google Calendar, and resulted in the poisoning of over 300 GitHub repositories. This highlights the vulnerability of the software supply chain and the need for enhanced security measures within developer environments.
The GlassWorm malware campaign has been actively targeting software developers since early 2025, leveraging their access to source code repositories, cloud platforms, and package registries. Attackers utilized trojanized VS Code extensions, distributed through the Microsoft VS Code Marketplace and Open VSX, to infiltrate developer workstations. The ultimate goal was to deploy a data-theft framework capable of harvesting credentials, exfiltrating cryptocurrency wallets, and profiling systems. Subsequent iterations introduced GlassWormRAT, a Websocket-based JavaScript RAT, to steal web browser data and execute arbitrary code, including installing Google Chrome extensions for further data collection.
The sophistication of the GlassWorm campaign was evident in its resilient C2 infrastructure, employing multiple layers of indirection including the Solana blockchain, BitTorrent DHT, and Google Calendar as resolvers. This multi-pronged approach aimed to evade takedowns and maintain persistent access to compromised systems. The operation resulted in the poisoning of over 300 GitHub repositories, demonstrating the potential for widespread impact. CrowdStrike’s coordinated takedown neutralized all four C2 channels simultaneously, preventing further instructions or payloads from reaching infected machines.
Attributed to likely Russia-based cybercriminals due to the targeting of CIS countries and the presence of Russian-language comments, the GlassWorm attack underscores the vulnerability of the software supply chain. The low barrier to entry for poisoning packages and the enormous potential blast radius make this a significant threat, particularly for organizations that rely on consuming software produced by others.
