GlassWorm is a multi-stage, self-propagating malware campaign targeting software developers through software supply-chain channels. First publicly identified in 2025, it spread through trojanized Visual Studio Code and OpenVSX extensions, compromised npm and Python packages, and downstream poisoning of GitHub repositories using stolen developer credentials. The campaign targeted developer workstations and ecosystems because they provide access to source repositories, package registries, CI/CD pipelines, cloud credentials, browser-stored secrets, and cryptocurrency wallets.
GlassWorm is associated with credential theft and broader post-compromise abuse. Reported behavior includes harvesting credentials from Mozilla Firefox and Chromium-based browsers, stealing developer tokens such as GitHub, npm, and OpenVSX credentials, collecting browser session data and cryptocurrency wallet information, and staging stolen data in temporary working directories before exfiltration. Later variants deployed a JavaScript remote access component known as GlassWormRAT, enabling arbitrary code execution and continued operator control. Infected hosts were also repurposed for covert infrastructure roles including proxying and hidden remote-access activity.
The malware emphasizes stealth and resilience. It has used invisible Unicode characters to conceal malicious logic inside extension source code, hidden VNC to conduct collection and communications without obvious user visibility, and locale-based execution guards that terminate on Russian-language or CIS-associated systems. On macOS, GlassWorm has established persistence through LaunchAgent-based startup execution. On Windows, reported variants monitored for USB device insertion and used WMI as part of trigger logic. The campaign also modified or abused trusted developer tooling and, in some reporting, hardware-wallet companion applications.
GlassWorm’s command-and-control architecture was unusually redundant. Observed mechanisms included Solana transaction memo fields as a dead-drop resolver, BitTorrent DHT-based configuration retrieval, Google Calendar event titles as dead-drop data, and direct VPS-hosted infrastructure. This multi-channel design complicated disruption and allowed operators to rotate or recover infrastructure without relying on a single service. A coordinated takedown by industry partners in May 2026 disrupted all known GlassWorm command channels.
The campaign has been linked in reporting to the broader developer-focused supply-chain threat environment that also includes Shai-Hulud-related activity, though GlassWorm is treated as its own malware operation. Public reporting has associated it with likely Russian-speaking cybercriminal operators based on geofencing behavior and Russian-language comments, but such attribution remains an assessment rather than definitive proof. GlassWorm is notable for combining worm-like propagation, credential theft, stealthy developer-tool compromise, and resilient command-and-control to create downstream supply-chain risk across Windows, macOS, and Linux environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These investigations have identified a central figure known online as "ResoluteXBF" with connections to South African-based infrastructure. Even though the group was relatively new when it emerged in 2010, it has rapidly evolved from the Shai-Hulud campaign to subsequent operations that involved malware such as GlassWorm...
A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections
Within a short period of time, the threat actor compromised more than 1,000 software packages and weaponized trusted development channels... Through compromise of CI runners, TeamPCP effectively converted trusted software distribution channels into malware delivery channels... downstream developers were able to retrieve them using package managers, GitHub Actions, Python libraries, NPM registries, and other software components that were configured to pull the latest releases from the repository.
Trojanized VSCode extensions were published to the OpenVSX marketplace, disguised as popular tools like time trackers and code formatters.
It then force-pushed malicious commits to every repository the victim’s account could reach, spreading the infection to any developer who later cloned those repositories.
File i.js JavaScript payload file written to script directory during execution
It used invisible Unicode characters to hide malicious logic inside extension source files, making the code appear as empty lines to human reviewers and automated tools alike.
The campaign we analyzed, however, uses a different and under-observed class of characters (variation selectors) that remain largely invisible to common tooling.
The injection preserves the original commit author and date, making it look like nothing in the project history has changed.
More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections
The next month, researchers discovered the Glassworm attack, which utilizes VS Code extensions to compromise developer machines.
Before doing anything visible, the malware validates the environment. It checks locale settings and will exit early on systems configured with Russian-language locales... It also probes for EDR software: CrowdStrike Falcon, SentinelOne, Carbon Black, and the StepSecurity Harden-Runner for GitHub Actions are all specifically detected.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Once active, GlassWorm harvested GitHub tokens, npm tokens, OpenVSX tokens, and cryptocurrency wallet data.
Glassworm ... is a self-propagating, credential-stealing worm ... later poisoned more than 300 GitHub repos using stolen credentials harvested in earlier Glassworm infections.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Glassworm steals GitHub tokens from multiple sources, including VS Code storage, the git credentials file, and local environment variables.
The malware checks the victim's locale, language settings, and timezone at runtime
Before doing anything visible, the malware validates the environment. It checks locale settings and will exit early on systems configured with Russian-language locales... It also probes for EDR software: CrowdStrike Falcon, SentinelOne, Carbon Black, and the StepSecurity Harden-Runner for GitHub Actions are all specifically detected.
CrowdStrike, together with Google and the Shadowserver Foundation, neutralized all four GlassWorm command-and-control channels on May 26, 2026.
Glassworm used invisible Unicode-based code injection, blockchain-based C2 infrastructure, and Google Calendar as a backup command server to turn infected developers’ machines into criminal proxy nodes.
The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives. | dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it.
It also used Google Calendar event titles as dead-drop locations for Base64-encoded C2 paths.
Direct server connections : Traditional C2 infrastructure hosted on commercial VPS providers served as the final payload delivery mechanism.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Self-propagating malware that uses Solana transaction metadata as a dead drop resolver, querying recent wallet transactions and decoding memo data to recover a Base64-encoded C2 URL.
A stealer distributed through malicious IDE extensions that installs a secondary malicious extension, exfiltrates crypto wallet data, environment variables, and other secrets, and installs a RAT on infected devices.
A Windows malware referenced for comparison that detected USB device insertion and displayed its own malicious wallet-related window after terminating the legitimate application.
Referenced as another supply-chain campaign known for locale-based execution gating, specifically exiting on Russian-language locales.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.