BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GlassWorm Botnet Disrupted After Targeting Devs

Major cybersecurity firms dismantle persistent GlassWorm developer-targeting botnet and its resilient infrastructure.

  • Major cybersecurity firms CrowdStrike, Google, and Shadowserver Foundation disrupted a persistent developer-targeting botnet named GlassWorm on May 27, 2026.
  • The botnet used trojanized VS Code extensions and malicious code packages to steal developer credentials, cryptocurrency wallets, and system data, according to researchers.
  • The takedown neutralized the botnet’s four distinct and resilient command-and-control channels simultaneously, cutting off infected machines from new instructions.

In a significant coordinated action on May 27, 2026, a coalition led by CrowdStrike successfully dismantled the command infrastructure of the GlassWorm botnet, a persistent cybercriminal campaign targeting software developers globally. The operation, conducted in partnership with Google and the Shadowserver Foundation, simultaneously disrupted all four of the botnet’s resilient command channels, according to a CrowdStrike report. This development highlights the escalating threat to the software supply chain, where a single compromised developer workstation can impact thousands of downstream organizations.

- Advertisement -

GlassWorm operators, described as “well-resourced and persistent,” had conducted a multi-pronged campaign since early 2025. They primarily used malicious VS Code extensions published on marketplaces to target developers using popular code editors, as detailed by researchers. The campaign’s end goal was to deploy a sophisticated data-theft framework capable of credential harvesting and cryptocurrency wallet exfiltration.

Once active, the malware aggressively searched infected hosts for developer credentials and crypto wallets. Consequently, infected systems were converted into covert infrastructure like proxies and remote execution nodes, providing attackers anonymized network access. This access allowed them to poison over 300 GitHub repositories using stolen credentials.

The botnet’s architecture was notably resilient, employing a combination of blockchain, peer-to-peer, and legitimate web services for command-and-control. However, the coordinated takedown neutralized all these channels, preventing infected machines from receiving new payloads. CrowdStrike attributed the activity to likely Russia-based cybercriminals, citing Russian-language code and execution safeguards for systems in CIS countries.

“The software supply chain remains one of the most consequential attack surfaces in modern computing,” CrowdStrike concluded. The firm warned that as long as developer environments remain under-protected, every organization that consumes software inherits significant risk from these supply chain attacks.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BlackRock’s Bitcoin ETF Lures New Investors to Entire ETF Market

BlackRock's spot Bitcoin ETF has attracted a significant number of first-time ETF investors.Many of...

Audit Gap Exposed As AI Finds Major Four-Year Crypto Bug

A critical four-year-old bug in ZCash's shielded pool, discovered in June 2026, wiped out...

Z.ai’s GLM-5.2 Nears Claude Opus, Beats GPT-5.5, MIT Licensed

Z.ai released the GLM-5.2 AI model, which performs within 1% of Claude Opus 4.8...

Strategy loses 40 years of dividend coverage in 7 months

Strategy lost 40 years of forecasted dividend coverage in just seven months.The coverage decline...

HIVE to deploy GPUs for Cohere in $220M AI cloud deal

HIVE Digital Technologies has signed a major three-year GPU cloud contract with Bell AI...

Must Read

A Beginner’s Guide To Cryptocurrency Mining

Cryptocurrency is considered one of the most popular forms of financial assets today. Many of these digital assets operate within blockchain technology which works...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading