#glassworm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #glassworm, aggregated by home.social.
-
#Glassworm #botnet disrupted after resilient C2 infrastructure takedown
-
#Glassworm #botnet disrupted after resilient C2 infrastructure takedown
-
Glassworm smantellato: CrowdStrike abbatte la botnet che prendeva di mira gli sviluppatori attraverso npm, PyPI e GitHub
Il 26 maggio 2026, CrowdStrike, Google e Shadowserver Foundation hanno eseguito un takedown coordinato di Glassworm, botnet attivo da oltre un anno che infettava sviluppatori attraverso estensioni VSCode trojanizzate, pacchetti npm/Python malevoli e repository GitHub avvelenati. Il C2 sfruttava blockchain Solana, BitTorrent DHT e Google Calendar come canali di resilienza. -
Glassworm smantellato: CrowdStrike abbatte la botnet che prendeva di mira gli sviluppatori attraverso npm, PyPI e GitHub
Il 26 maggio 2026, CrowdStrike, Google e Shadowserver Foundation hanno eseguito un takedown coordinato di Glassworm, botnet attivo da oltre un anno che infettava sviluppatori attraverso estensioni VSCode trojanizzate, pacchetti npm/Python malevoli e repository GitHub avvelenati. Il C2 sfruttava blockchain Solana, BitTorrent DHT e Google Calendar come canali di resilienza. -
CrowdStrike disrupts Glassworm botnet with global takedown
In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet in a global takedown, cutting off its operators from infected machines worldwide. The infected machines now harmlessly connect to a CrowdStrike-controlled IP address, rendering the botnet useless.
#BotnetTakedown #EmergingThreats #Glassworm #Crowdstrike #Google
-
CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
#botnet #crowdstrike #github #glassworm #google #shadowserver
-
CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
#botnet #crowdstrike #github #glassworm #google #shadowserver
-
CrowdStrike dismantles Glassworm botnet targeting open-source supply chain
In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet, crippling its ability to target the open-source supply chain. By taking down four key servers, CrowdStrike has forced the attackers to regroup and rebuild, buying time for the industry to stay one step ahead.
#BotnetDisruption #Glassworm #OpensourceSupplyChain #EmergingThreats #Crowdstrike
-
CrowdStrike dismantles Glassworm botnet targeting open-source supply chain
In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet, crippling its ability to target the open-source supply chain. By taking down four key servers, CrowdStrike has forced the attackers to regroup and rebuild, buying time for the industry to stay one step ahead.
#BotnetDisruption #Glassworm #OpensourceSupplyChain #EmergingThreats #Crowdstrike
-
Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet
#GlassWorm
https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/ -
Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet
#GlassWorm
https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/ -
CrowdStrike and Google Disrupt Glassworm Botnet Infrastructure
In a major win for cybersecurity, a powerful collaboration between CrowdStrike, Google, and the Shadowserver Foundation successfully dismantled the Glassworm botnet by simultaneously taking down all four of its command-and-control channels. This bold move cut off the botnet's operators from infected devices, preventing further…
#BotnetDisruption #Glassworm #EmergingThreats #CommandAndControl #Blockchain
-
Glassworm botnet disrupted by takedown of resilient C2 infrastructure
In a major win for cybersecurity, researchers from CrowdStrike, Google, and The Shadowserver Foundation have successfully disrupted the Glassworm botnet by dismantling its complex command-and-control infrastructure. This takedown cuts off the lifelines of the threat actors, halting their campaigns that had been ongoing since…
#BotnetTakedown #Glassworm #C2Infrastructure #Blockchain #Peertopeer
-
CrowdStrike Disrupts GlassWorm Malware's Global Supply Chain Attack Infrastructure
In a major win for cybersecurity, CrowdStrike teamed up with Google and the Shadowserver Foundation to dismantle the global infrastructure behind the GlassWorm malware attack, crippling its ability to issue commands or deliver new payloads to infected machines. This coordinated operation targeted and neutralized…
#Glassworm #MalwareOperations #SupplyChain #EmergingThreats #CicdPipeline
-
GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware
La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software. -
GlassWorm muta ancora: 73 estensioni “sleeper” su Open VSX pronte a svegliarsi come malware
La campagna GlassWorm torna con 73 nuove estensioni dormanti sul marketplace Open VSX. Socket ha rilevato nuove attivazioni malware da estensioni che erano parse innocue per settimane: un escalation preoccupante per l'intera pipeline di sviluppo software. -
GlassWorm goes native: New Zig dropper infects every IDE on your machine
#GlassWorm
https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine -
GlassWorm goes native: New Zig dropper infects every IDE on your machine
#GlassWorm
https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine -
GlassWorm: il worm che infetta tutti gli IDE tramite un’estensione OpenVSX contraffatta
Un dropper compilato in Zig si propaga da un'estensione fake WakaTime su OpenVSX verso tutti gli IDE VS Code-compatibili presenti sulla macchina, deployando un RAT con C2 su blockchain Solana e un'estensione Chrome per il furto di sessioni. Analisi tecnica completa della campagna GlassWorm. -
GlassWorm: il worm che infetta tutti gli IDE tramite un’estensione OpenVSX contraffatta
Un dropper compilato in Zig si propaga da un'estensione fake WakaTime su OpenVSX verso tutti gli IDE VS Code-compatibili presenti sulla macchina, deployando un RAT con C2 su blockchain Solana e un'estensione Chrome per il furto di sessioni. Analisi tecnica completa della campagna GlassWorm. -
El malware GlassWorm ataca a los Mac con monederos de criptomonedas
#ciberseguridad #AppleSecurity #GlassWorm
https://mecambioamac.com/el-malware-glassworm-ataca-a-los-mac-con-monederos-de-criptomonedas/
-
ForceMemo: malware ukrywany w repozytoriach przez force-push
Badacze bezpieczeństwa z StepSecurity odkryli nową kampanię malware, w której atakujący przejmuje masowo konta programistów na GitHub i wstrzykuje złośliwe oprogramowanie do setek repozytoriów. Pierwszą aktywność odnotowano 8 marca 2026 roku, ale według ustaleń badaczy kampania wciąż trwa i przejmowane są kolejne repozytoria. Kampania – nazwana przez badaczy ForceMemo –...
#Aktualności #Github #Glassworm #Malware
https://sekurak.pl/forcememo-malware-ukrywany-w-repozytoriach-przez-force-push/
-
ForceMemo: malware ukrywany w repozytoriach przez force-push
Badacze bezpieczeństwa z StepSecurity odkryli nową kampanię malware, w której atakujący przejmuje masowo konta programistów na GitHub i wstrzykuje złośliwe oprogramowanie do setek repozytoriów. Pierwszą aktywność odnotowano 8 marca 2026 roku, ale według ustaleń badaczy kampania wciąż trwa i przejmowane są kolejne repozytoria. Kampania – nazwana przez badaczy ForceMemo –...
#Aktualności #Github #Glassworm #Malware
https://sekurak.pl/forcememo-malware-ukrywany-w-repozytoriach-przez-force-push/
-
The most interesting supply chain attack I've ever seen: #trivy
The attack is really bizarre. I learned a lot about GitHub Actions and how the attack was performed.
- https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
- https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
- https://ramimac.me/trivy-teampcp/#timeline
- https://snyk.io/articles/trivy-github-actions-supply-chain-compromise/#cybersecurity #supplychain #github #glassworm #githubactions #attack #TeamPCP #c2
-
The most interesting supply chain attack I've ever seen: #trivy
The attack is really bizarre. I learned a lot about GitHub Actions and how the attack was performed.
- https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
- https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation
- https://ramimac.me/trivy-teampcp/#timeline
- https://snyk.io/articles/trivy-github-actions-supply-chain-compromise/#cybersecurity #supplychain #github #glassworm #githubactions #attack #TeamPCP #c2
-
#GlassWorm malware hides in invisible open-source code. Via @scientific_american #CyberSecurity
GlassWorm malware hides in inv... -
Der "#Glassworm" treibt immer mehr Unwesen - inside-it.ch https://www.inside-it.ch/der-glassworm-treibt-immer-mehr-unwesen-20260318 #Malware
-
Der "#Glassworm" treibt immer mehr Unwesen - inside-it.ch https://www.inside-it.ch/der-glassworm-treibt-immer-mehr-unwesen-20260318 #Malware
-
#GlassWorm compromised an #npm maintainer account, pushing 3 waves of malware across packages with 134K monthly downloads.
Endor Labs tracked 11 compromised versions across 4 packages and mapped the full infection chain + IoCs.
https://www.endorlabs.com/learn/npm-is-serving-malware-to-134k-developers
-
Im vergangenen Jahr hatte die unsichtbare Schadsoftware Glassworm mehrfach ihr Unwesen getrieben. Jetzt ist der gefährliche Wurm mit einer neuen Angriffswelle zurückgekehrt. Im Visier sind einmal mehr GitHub-Repositorys.
https://t3n.de/news/github-schadsoftware-glassworm-1734075/
#Schadsoftware #Glassworm #GitHub #Wurm #Angriffswelle #Gefahr
-
Tiens, plot twist ! le bouzin pivote vers windows
"On March 16, a new Solana memo appeared on the published #GlassWorm wallet (28PKnu, documented by Truesec in October 2025) at 11:42 UTC with a kill-switch toggle set to OFF and a live payload URL. The campaign had reactivated. The payload was not the macOS stealer from Parts 1 and 2. It was a 202KB JavaScript file targeting Windows, bundling native DLLs, a Chrome browser extension disguised as "Google Docs Offline", a DPAPI credential dumper, and exfiltration to a previously unseen server."
👇
https://codeberg.org/tip-o-deincognito/glassworm-writeup/src/branch/main/PART3.md -
Glassworm Hides Malware in Invisible Unicode Across 151+ Repos
#GitHub #Cybersecurity #Malware #VSCode #npm #OpenSource #Developers #SoftwareDevelopment #Cybercrime #Hackers #SecurityVulnerabilities #Microsoft #Software #BigTech #VSCodeExtension #GlassWorm #OpenVSX
-
Glassworm Hides Malware in Invisible Unicode Across 151+ Repos
#GitHub #Cybersecurity #Malware #VSCode #npm #OpenSource #Developers #SoftwareDevelopment #Cybercrime #Hackers #SecurityVulnerabilities #Microsoft #Software #BigTech #VSCodeExtension #GlassWorm #OpenVSX
-
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories
#GlassWorm
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode -
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories
#GlassWorm
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode -
🚨 Oh no! The dreaded #Glassworm is back, like a transparent hacker on a mission to confuse developers with invisible #Unicode attacks. With 150 #GitHub repositories compromised, the solution is a dizzying list of acronyms and jargon that promises to protect your code, but only if you squint hard enough to see it! 🐛🔍 #SecurityTheater
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode #InvisibleAttacks #SecurityThreat #DeveloperConfusion #HackerNews #ngated -
🚨 Oh no! The dreaded #Glassworm is back, like a transparent hacker on a mission to confuse developers with invisible #Unicode attacks. With 150 #GitHub repositories compromised, the solution is a dizzying list of acronyms and jargon that promises to protect your code, but only if you squint hard enough to see it! 🐛🔍 #SecurityTheater
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode #InvisibleAttacks #SecurityThreat #DeveloperConfusion #HackerNews #ngated -
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode
#HackerNews #Glassworm #Invisible #Unicode #Attacks #Cybersecurity #GitHub #Repositories
-
Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode
#HackerNews #Glassworm #Invisible #Unicode #Attacks #Cybersecurity #GitHub #Repositories
-
When I say "IT mostly just runs in circles" I mean it: https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/
This article from 2026 describes something I've been fighting with ~17 years ago. Sure, slightly more clever payload and different delivery method, but in principle nothing new: https://github.com/MichalBryxi/Apache-fork-hack-finder-cleaner/tree/master
-
When I say "IT mostly just runs in circles" I mean it: https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/
This article from 2026 describes something I've been fighting with ~17 years ago. Sure, slightly more clever payload and different delivery method, but in principle nothing new: https://github.com/MichalBryxi/Apache-fork-hack-finder-cleaner/tree/master
-
RE: https://infosec.exchange/@_r_netsec/116220859869337905
Waah, joli boulot.
Je me demande qui en est l’auteur.lecture technique très intéressante.
Une analyse statique complétée par du monitoring comportementale réseau qui plonge dans les entrailles du ver infostealer macOS injecté dans un plugin VS Code lors de la campagne Glassworm v2.. 👀C’est balaise et résilient, avec une belle répartition des tâches de vol entre AppleScript et Node.js. :amaze:
Les échantillons déobfusqués ont aussi été mis à disposition sur #malwarebazaar
https://bazaar.abuse.ch/sample/d72c1c75958ad7c68ef2fb2480fa9ebe185e457f3b62047b31565857fa06a51a/
#CyberVeille #MacSecurity #macOS #Malware #ThreatIntel #Glassworm
👇 -
Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack https://www.securityweek.com/open-vsx-publisher-account-hijacked-in-fresh-glassworm-attack/ #SupplyChainSecurity #Malware&Threats #Macmalware #GlassWorm #malware
-
Glassworm malware is now coming for Macs
#GlassWorm
https://moonlock.com/self-replicating-glassworm-infecting-macs -
#GlassWorm Malware Abuses Open Source Open VSX To Target #macOS Developers
-
GlassWorm has resurfaced with 24 malicious extensions posing as popular developer tools across Visual Studio Marketplace and Open VSX. The campaign uses Rust implants, Solana-based C2, and inflated download stats to slip harmful updates into trusted environments.
This wave shows how supply-chain attacks continue evolving by blending seamlessly into developer workflows.
What protections do you think dev ecosystems should prioritize next?
Follow us for consistent, unbiased cybersecurity coverage.
#infosec #glassworm #supplychainsecurity #devsecops #vscode #openvsx #malware #threatintel #securityresearch #technadu
-
Glassworm's resurgence
#GlassWorm
https://secureannex.com/blog/glassworm-continued/ -
Unsichtbarer Wurm in Visual Studio Extensions: #GlassWorm lebt | Developer https://www.heise.de/news/Schadsoftware-weiter-aktiv-GlassWorm-erneut-in-Open-VSX-Paketen-gefunden-11073146.html #Malware