BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GlassWorm Attack Steals Data Via Fake Chrome Extension

GlassWorm evolves into a multi-stage malware using Solana blockchain and AI tool impersonations.

  • GlassWorm attackers now use a multi-stage framework that steals data and delivers a remote access trojan via a malicious Chrome extension.
  • The malware employs the Solana blockchain to hide its command server and specifically targets cryptocurrency hardware wallets with phishing windows.
  • A new Python tool called glassworm-hunter has been released to help developers scan their systems for these payloads.
  • The campaign has evolved to impersonate trusted npm packages, including an AI development tool called the WaterCrawl MCP server.

Cybersecurity researchers revealed on March 25, 2026, that the persistent GlassWorm campaign has evolved into a sophisticated multi-stage attack framework. This new evolution, as detailed by Aikido security researcher Ilyas Makari, delivers a powerful information-stealing Google Chrome extension and a remote access trojan (RAT). The initial infection spreads through poisoned packages on trusted platforms like npm, PyPI, and GitHub.

- Advertisement -

The attack chain cleverly avoids systems with Russian locales and uses Solana blockchain transactions as a dead drop resolver to find its command server. Consequently, it downloads operating system-specific payloads designed for comprehensive data theft. This stage-two framework harvests credentials, exfiltrates cryptocurrency wallets, and profiles the victim’s system before sending the data to an external server.

Once data is transmitted, the malware fetches additional components including a .NET binary that performs hardware wallet phishing. This binary uses Windows Management Instrumentation to detect when a Ledger or Trezor wallet is connected and displays a fake error window to steal the 24-word recovery phrase. The malware persistently reopens the phishing window if closed and kills legitimate Ledger Live processes on the host machine.

Meanwhile, a separate JavaScript RAT component uses a Distributed Hash Table (DHT) and the Solana blockchain to establish communication. This RAT can run commands to deploy a hidden remote desktop, operate a SOCKS proxy, and execute arbitrary code. It also force-installs a malicious Chrome extension masquerading as “Google Docs Offline,” which steals cookies, keystrokes, screenshots, and even monitors specific sites like Bybit.

Researchers noted this campaign represents GlassWorm‘s first confirmed move into the AI-assisted development ecosystem by publishing a malicious npm package impersonating the WaterCrawl MCP server. In response, Polish cybersecurity company AFINE has published an open-source Python tool to help developers scan for these stealthy payloads locally.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OpenAI Pledges $250M to Ease AI Job Disruption Fallout

The OpenAI Foundation commits an initial $250 million to grants and partnerships aimed at...

Bitwise BHYP ETF hits record $19M daily inflow

Bitwise’s BHYP ETF secured a record $19 million inflow on Tuesday, becoming the world's...

Stake DAO Hacked in vsdCRV Minting Exploit

An attacker used a compromised private key to mint 5.4 trillion vsdCRV tokens on...

HTX Disputes UK Sanctions Over Russian Finance Claims

The UK sanctioned Huobi Global S.A., alleging it helped move funds through a shadow...

GlassWorm Botnet Disrupted After Targeting Devs

Major cybersecurity firms CrowdStrike, Google, and Shadowserver Foundation disrupted a persistent developer-targeting botnet named...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading