< Back to all clusters
[TECHNOLOGY] · 5 sources

Glassworm malware takedown halts developer supply‑chain attacks

A coordinated operation by CrowdStrike, Google and the Shadowserver Foundation on May 26‑27, 2026 disrupted the Glassworm botnet, which had infiltrated open‑source software projects, VS Code extensions, npm and PyPI packages, and more than 300 GitHub repositories. The malware, known as GlasswormRAT, stole developer credentials and cryptocurrency wallet data, and it used four resilient command‑and‑control channels – the Solana blockchain, Google Calendar, the BitTorrent Distributed Hash Table and commercial VPS servers – to receive instructions.

The takedown simultaneously neutralised all four channels, preventing further instructions or payloads from reaching infected machines. Analysts attribute the campaign to a well‑resourced, likely Russia‑based group. By dismantling the infrastructure, the effort raises the operational costs for the attackers and highlights the fragility of the software supply‑chain trust model for developers worldwide.