GlassWorm is a software supply-chain threat actor focused on compromising developer ecosystems and downstream enterprise environments. Active since at least 2025, the actor has targeted developers through trojanized Visual Studio Code and OpenVSX extensions, malicious or compromised npm and Python packages, and hijacked GitHub repositories. Reported activity includes poisoning more than 300 GitHub repositories using stolen developer credentials and compromising hundreds of software artifacts across repositories, packages, and extensions. GlassWorm’s operations center on developer credential theft, secret harvesting, and follow-on access into CI/CD and software distribution paths. Observed malware and loaders have stolen tokens, credentials, browser data, cryptocurrency wallet data, SSH and cloud-related secrets, and other developer environment material. The actor has used stolen credentials to modify legitimate repositories and propagate malicious code through trusted update channels, including force-pushed malicious commits and sleeper extensions later weaponized through updates. A defining feature of GlassWorm tradecraft is resilient, multi-layered command-and-control design. Multiple reports associate the actor with dead-drop and decentralized resolution mechanisms using Solana transaction memo fields, and some reporting also links GlassWorm to fallback or parallel channels using BitTorrent DHT and Google Calendar, with conventional servers used for payload delivery. This architecture is intended to preserve operator access and complicate takedown efforts. Researchers and industry partners later disrupted all four known GlassWorm command-and-control channels in a coordinated operation. GlassWorm has repeatedly abused trust relationships in developer tooling. Documented techniques include hiding malicious JavaScript in invisible Unicode characters, using obfuscated or runtime-decrypted loaders, abusing extension dependency and extension pack mechanisms for transitive installation, cloning legitimate extension listings to exploit cross-registry trust gaps, and deploying native compiled components outside the normal extension sandbox. Later variants used bundled native binaries and thin-loader designs to spread across compatible IDEs such as VS Code forks and related development environments. The actor has also been linked to malware referred to as GlassWASM and GlasswormRAT. Reported capabilities associated with these components include remote code execution, credential and wallet theft, browser data theft, persistence, hidden remote access, SOCKS proxying, and installation of malicious browser extensions for surveillance and theft. Some reporting describes geofencing logic that avoids execution on Russian or broader CIS systems, and Russian-language code comments have been cited in attribution assessments. Attribution to Russian-speaking operators has been reported based on CIS-avoidance logic, Russian-language comments, and broader tradecraft patterns, but not all reporting treats this attribution as fully confirmed. High-confidence characterization supports GlassWorm as a financially motivated cybercriminal supply-chain actor targeting developers, open-source ecosystems, and software distribution trust paths.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with a supply-chain campaign involving trojanized Open VSX extensions delivering GlassWASM, using WebAssembly for obfuscation and the Solana blockchain as a dead-drop C2 mechanism.
Used trojanized extensions and compromised packages to poison GitHub repositories at scale using stolen credentials.
Used trojanized extensions and compromised packages to poison GitHub repositories via stolen credentials as part of supply chain botnet operations.
An operator conducting supply-chain attacks against VS Code extensions and using Solana memo fields for command-and-control resolution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.