GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

The simultaneous shutdown of all command-and-control (C2) channels connected to GlassWorm, a persistent software chain campaign that targets software developers through malicious packages and extensions, has been announced by CrowdStrike in collaboration with Google and the Shadowserver Foundation.

Software developers, who have access to source code repositories, cloud platforms, CI/CD pipelines, and package registries, have been the focus of GlassWorm operators since at least early 2025, according to CrowdStrike.

The development coincides with developers becoming more and more lucrative targets for software supply chain attacks, which allow attackers to utilize a single compromised workstation to simultaneously affect thousands of users and downstream firms.

Since its debut last year, GlassWorm has carried out a “multi-pronged campaign” that targets users of VS Code forks including Cursor read more about GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *