BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GlassWorm Botnet Disrupted After Targeting Devs

Major cybersecurity firms dismantle persistent GlassWorm developer-targeting botnet and its resilient infrastructure.

  • Major cybersecurity firms CrowdStrike, Google, and Shadowserver Foundation disrupted a persistent developer-targeting botnet named GlassWorm on May 27, 2026.
  • The botnet used trojanized VS Code extensions and malicious code packages to steal developer credentials, cryptocurrency wallets, and system data, according to researchers.
  • The takedown neutralized the botnet’s four distinct and resilient command-and-control channels simultaneously, cutting off infected machines from new instructions.

In a significant coordinated action on May 27, 2026, a coalition led by CrowdStrike successfully dismantled the command infrastructure of the GlassWorm botnet, a persistent cybercriminal campaign targeting software developers globally. The operation, conducted in partnership with Google and the Shadowserver Foundation, simultaneously disrupted all four of the botnet’s resilient command channels, according to a CrowdStrike report. This development highlights the escalating threat to the software supply chain, where a single compromised developer workstation can impact thousands of downstream organizations.

- Advertisement -

GlassWorm operators, described as “well-resourced and persistent,” had conducted a multi-pronged campaign since early 2025. They primarily used malicious VS Code extensions published on marketplaces to target developers using popular code editors, as detailed by researchers. The campaign’s end goal was to deploy a sophisticated data-theft framework capable of credential harvesting and cryptocurrency wallet exfiltration.

Once active, the malware aggressively searched infected hosts for developer credentials and crypto wallets. Consequently, infected systems were converted into covert infrastructure like proxies and remote execution nodes, providing attackers anonymized network access. This access allowed them to poison over 300 GitHub repositories using stolen credentials.

The botnet’s architecture was notably resilient, employing a combination of blockchain, peer-to-peer, and legitimate web services for command-and-control. However, the coordinated takedown neutralized all these channels, preventing infected machines from receiving new payloads. CrowdStrike attributed the activity to likely Russia-based cybercriminals, citing Russian-language code and execution safeguards for systems in CIS countries.

“The software supply chain remains one of the most consequential attack surfaces in modern computing,” CrowdStrike concluded. The firm warned that as long as developer environments remain under-protected, every organization that consumes software inherits significant risk from these supply chain attacks.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

HTX Disputes UK Sanctions Over Russian Finance Claims

The UK sanctioned Huobi Global S.A., alleging it helped move funds through a shadow...

Shiba Inu (SHIB) Down 93% From Peak: What’s Next?

Shiba Inu (SHIB) has declined by over 93% from its all-time high, according to...

First “Rug Pull” Charges Under Korea’s New Crypto Law

South Korean prosecutors charged five people with a "rug pull" of the CatFi meme...

XRP Hits Nearly 5-Year Low for Trader Losses

XRP's 30-day Market Value to Realized Value (MVRV) ratio has plunged to its lowest...

Solana Falls Over 50% In a Year: Is It Time to Sell?

Solana (SOL) has experienced significant declines across multiple timeframes, dropping 51.9% year-over-year.The broader cryptocurrency...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading