CrowdStrike and Google Disrupt Glassworm Botnet Targeting Developers (crowdstrike.com)
- CrowdStrike, Google, and Shadowserver Foundation executed coordinated takedown of Glassworm botnet.
- Botnet targeted developers via supply chain: VSCode extensions, npm/PyPI packages, GitHub repos.
- Four resilient C2 channels (Solana, BitTorrent DHT, Google Calendar, VPS) simultaneously disrupted.
- Infected machines beacon to 164.92.88.210; YARA rules available.
- Operators suspected to be Russian-based.
"On May 26, 2026, CrowdStrike, Google, and the Shadowserver Foundation conducted a coordinated takedown of the Glassworm botnet, which had been targeting software developers since early 2025. The botnet used trojanized VSCode extensions, compromised npm and Python packages, and poisoned over 300 GitHub repositories to compromise developer workstations. Its command-and-control infrastructure relied on four resilient channels: Solana blockchain transactions, BitTorrent DHT, Google Calendar events, and direct VPS servers. All four channels were simultaneously disrupted, severing the operators' ability to issue new commands. Operators are suspected to be based in Russia. Infected machines now beacon to a CrowdStrike-operated IP (164.92.88.210)."
no comments yet.