home.social

#glassworm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #glassworm, aggregated by home.social.

fetched live
  1. Glassworm smantellato: CrowdStrike abbatte la botnet che prendeva di mira gli sviluppatori attraverso npm, PyPI e GitHub

    Il 26 maggio 2026, CrowdStrike, Google e Shadowserver Foundation hanno eseguito un takedown coordinato di Glassworm, botnet attivo da oltre un anno che infettava sviluppatori attraverso estensioni VSCode trojanizzate, pacchetti npm/Python malevoli e repository GitHub avvelenati. Il C2 sfruttava blockchain Solana, BitTorrent DHT e Google Calendar come canali di resilienza.

    insicurezzadigitale.com/glassw

  2. Glassworm smantellato: CrowdStrike abbatte la botnet che prendeva di mira gli sviluppatori attraverso npm, PyPI e GitHub

    Il 26 maggio 2026, CrowdStrike, Google e Shadowserver Foundation hanno eseguito un takedown coordinato di Glassworm, botnet attivo da oltre un anno che infettava sviluppatori attraverso estensioni VSCode trojanizzate, pacchetti npm/Python malevoli e repository GitHub avvelenati. Il C2 sfruttava blockchain Solana, BitTorrent DHT e Google Calendar come canali di resilienza.

    insicurezzadigitale.com/glassw

  3. CrowdStrike disrupts Glassworm botnet with global takedown

    In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet in a global takedown, cutting off its operators from infected machines worldwide. The infected machines now harmlessly connect to a CrowdStrike-controlled IP address, rendering the botnet useless.

    osintsights.com/crowdstrike-di

    #BotnetTakedown #EmergingThreats #Glassworm #Crowdstrike #Google

  4. CrowdStrike dismantles Glassworm botnet targeting open-source supply chain

    In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet, crippling its ability to target the open-source supply chain. By taking down four key servers, CrowdStrike has forced the attackers to regroup and rebuild, buying time for the industry to stay one step ahead.

    osintsights.com/crowdstrike-di

    #BotnetDisruption #Glassworm #OpensourceSupplyChain #EmergingThreats #Crowdstrike

  5. CrowdStrike dismantles Glassworm botnet targeting open-source supply chain

    In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet, crippling its ability to target the open-source supply chain. By taking down four key servers, CrowdStrike has forced the attackers to regroup and rebuild, buying time for the industry to stay one step ahead.

    osintsights.com/crowdstrike-di

    #BotnetDisruption #Glassworm #OpensourceSupplyChain #EmergingThreats #Crowdstrike

  6. CrowdStrike and Google Disrupt Glassworm Botnet Infrastructure

    In a major win for cybersecurity, a powerful collaboration between CrowdStrike, Google, and the Shadowserver Foundation successfully dismantled the Glassworm botnet by simultaneously taking down all four of its command-and-control channels. This bold move cut off the botnet's operators from infected devices, preventing further…

    osintsights.com/crowdstrike-an

    #BotnetDisruption #Glassworm #EmergingThreats #CommandAndControl #Blockchain

  7. Glassworm botnet disrupted by takedown of resilient C2 infrastructure

    In a major win for cybersecurity, researchers from CrowdStrike, Google, and The Shadowserver Foundation have successfully disrupted the Glassworm botnet by dismantling its complex command-and-control infrastructure. This takedown cuts off the lifelines of the threat actors, halting their campaigns that had been ongoing since…

    osintsights.com/glassworm-botn

    #BotnetTakedown #Glassworm #C2Infrastructure #Blockchain #Peertopeer

  8. CrowdStrike Disrupts GlassWorm Malware's Global Supply Chain Attack Infrastructure

    In a major win for cybersecurity, CrowdStrike teamed up with Google and the Shadowserver Foundation to dismantle the global infrastructure behind the GlassWorm malware attack, crippling its ability to issue commands or deliver new payloads to infected machines. This coordinated operation targeted and neutralized…

    osintsights.com/crowdstrike-di

    #Glassworm #MalwareOperations #SupplyChain #EmergingThreats #CicdPipeline

  9. GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware

    La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software.

    insicurezzadigitale.com/glassw

  10. GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware

    La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software.

    insicurezzadigitale.com/glassw

  11. GlassWorm: il worm che infetta tutti gli IDE tramite un’estensione OpenVSX contraffatta

    Un dropper compilato in Zig si propaga da un'estensione fake WakaTime su OpenVSX verso tutti gli IDE VS Code-compatibili presenti sulla macchina, deployando un RAT con C2 su blockchain Solana e un'estensione Chrome per il furto di sessioni. Analisi tecnica completa della campagna GlassWorm.

    insicurezzadigitale.com/glassw

  12. GlassWorm: il worm che infetta tutti gli IDE tramite un’estensione OpenVSX contraffatta

    Un dropper compilato in Zig si propaga da un'estensione fake WakaTime su OpenVSX verso tutti gli IDE VS Code-compatibili presenti sulla macchina, deployando un RAT con C2 su blockchain Solana e un'estensione Chrome per il furto di sessioni. Analisi tecnica completa della campagna GlassWorm.

    insicurezzadigitale.com/glassw

  13. ForceMemo: malware ukrywany w repozytoriach przez force-push

    Badacze bezpieczeństwa z StepSecurity odkryli nową kampanię malware, w której atakujący przejmuje masowo konta programistów na GitHub i wstrzykuje złośliwe oprogramowanie do setek repozytoriów. Pierwszą aktywność odnotowano 8 marca 2026 roku, ale według ustaleń badaczy kampania wciąż trwa i przejmowane są kolejne repozytoria. Kampania – nazwana przez badaczy ForceMemo –...

    #Aktualności #Github #Glassworm #Malware

    sekurak.pl/forcememo-malware-u

  14. ForceMemo: malware ukrywany w repozytoriach przez force-push

    Badacze bezpieczeństwa z StepSecurity odkryli nową kampanię malware, w której atakujący przejmuje masowo konta programistów na GitHub i wstrzykuje złośliwe oprogramowanie do setek repozytoriów. Pierwszą aktywność odnotowano 8 marca 2026 roku, ale według ustaleń badaczy kampania wciąż trwa i przejmowane są kolejne repozytoria. Kampania – nazwana przez badaczy ForceMemo –...

    #Aktualności #Github #Glassworm #Malware

    sekurak.pl/forcememo-malware-u

  15. #GlassWorm compromised an #npm maintainer account, pushing 3 waves of malware across packages with 134K monthly downloads.

    Endor Labs tracked 11 compromised versions across 4 packages and mapped the full infection chain + IoCs.

    endorlabs.com/learn/npm-is-ser

  16. Im vergangenen Jahr hatte die unsichtbare Schadsoftware Glassworm mehrfach ihr Unwesen getrieben. Jetzt ist der gefährliche Wurm mit einer neuen Angriffswelle zurückgekehrt. Im Visier sind einmal mehr GitHub-Repositorys.

    t3n.de/news/github-schadsoftwa

    #Schadsoftware #Glassworm #GitHub #Wurm #Angriffswelle #Gefahr

  17. Tiens, plot twist ! le bouzin pivote vers windows

    "On March 16, a new Solana memo appeared on the published #GlassWorm wallet (28PKnu, documented by Truesec in October 2025) at 11:42 UTC with a kill-switch toggle set to OFF and a live payload URL. The campaign had reactivated. The payload was not the macOS stealer from Parts 1 and 2. It was a 202KB JavaScript file targeting Windows, bundling native DLLs, a Chrome browser extension disguised as "Google Docs Offline", a DPAPI credential dumper, and exfiltration to a previously unseen server."
    👇
    codeberg.org/tip-o-deincognito

  18. 🚨 Oh no! The dreaded #Glassworm is back, like a transparent hacker on a mission to confuse developers with invisible #Unicode attacks. With 150 #GitHub repositories compromised, the solution is a dizzying list of acronyms and jargon that promises to protect your code, but only if you squint hard enough to see it! 🐛🔍 #SecurityTheater
    aikido.dev/blog/glassworm-retu #InvisibleAttacks #SecurityThreat #DeveloperConfusion #HackerNews #ngated

  19. 🚨 Oh no! The dreaded #Glassworm is back, like a transparent hacker on a mission to confuse developers with invisible #Unicode attacks. With 150 #GitHub repositories compromised, the solution is a dizzying list of acronyms and jargon that promises to protect your code, but only if you squint hard enough to see it! 🐛🔍 #SecurityTheater
    aikido.dev/blog/glassworm-retu #InvisibleAttacks #SecurityThreat #DeveloperConfusion #HackerNews #ngated

  20. When I say "IT mostly just runs in circles" I mean it: arstechnica.com/security/2026/

    This article from 2026 describes something I've been fighting with ~17 years ago. Sure, slightly more clever payload and different delivery method, but in principle nothing new: github.com/MichalBryxi/Apache-

    #Glassworm #Unicode #InvisibleCharacters #Whitespace #Hack

  21. When I say "IT mostly just runs in circles" I mean it: arstechnica.com/security/2026/

    This article from 2026 describes something I've been fighting with ~17 years ago. Sure, slightly more clever payload and different delivery method, but in principle nothing new: github.com/MichalBryxi/Apache-

    #Glassworm #Unicode #InvisibleCharacters #Whitespace #Hack

  22. RE: infosec.exchange/@_r_netsec/11

    Waah, joli boulot.
    Je me demande qui en est l’auteur.

    lecture technique très intéressante.
    Une analyse statique complétée par du monitoring comportementale réseau qui plonge dans les entrailles du ver infostealer macOS injecté dans un plugin VS Code lors de la campagne Glassworm v2.. 👀

    C’est balaise et résilient, avec une belle répartition des tâches de vol entre AppleScript et Node.js. :amaze:

    Les échantillons déobfusqués ont aussi été mis à disposition sur #malwarebazaar

    bazaar.abuse.ch/sample/d72c1c7

    #CyberVeille #MacSecurity #macOS #Malware #ThreatIntel #Glassworm
    👇

  23. GlassWorm has resurfaced with 24 malicious extensions posing as popular developer tools across Visual Studio Marketplace and Open VSX. The campaign uses Rust implants, Solana-based C2, and inflated download stats to slip harmful updates into trusted environments.

    This wave shows how supply-chain attacks continue evolving by blending seamlessly into developer workflows.

    What protections do you think dev ecosystems should prioritize next?

    Follow us for consistent, unbiased cybersecurity coverage.

    #infosec #glassworm #supplychainsecurity #devsecops #vscode #openvsx #malware #threatintel #securityresearch #technadu