GlassWorm is a self-propagating software supply-chain malware campaign and botnet that targets software developers across trusted development ecosystems. First publicly identified in 2025, it has been distributed through trojanized Visual Studio Code and OpenVSX extensions, compromised npm and Python packages, and malicious changes pushed into source-code repositories using stolen developer credentials. The campaign has targeted developer environments on Windows, macOS, and Linux, including users of VS Code forks such as Cursor, Windsurf, Positron, and VSCodium.
Its core objective is credential and secret theft from developer workstations and build environments. Reported targets include GitHub, npm, and OpenVSX tokens, browser data, cloud and CI/CD access material, and cryptocurrency wallet information. GlassWorm has also been observed modifying hardware wallet applications and using wallet-focused theft workflows. On compromised systems it stages collected data locally before exfiltration, and later variants deploy a JavaScript remote access component commonly referred to as GlassWormRAT, enabling arbitrary code execution and broader post-compromise control.
GlassWorm is notable for stealth and propagation tradecraft tailored to developer tooling. Early variants hid malicious logic in extension source code using invisible Unicode characters so code appeared blank or benign to reviewers and some automated tooling. The malware validates its environment and exits on systems configured for Russian-language locales or CIS-related settings, a behavior repeatedly observed across the campaign. On macOS it has established persistence through a LaunchAgent. Additional reporting indicates infected hosts may be repurposed as covert infrastructure, including proxying and remote execution nodes.
Propagation relies heavily on stolen credentials and abuse of trusted update paths. After infecting a developer machine, GlassWorm has been reported to force-push malicious commits into repositories accessible to the victim, poisoning hundreds of repositories and creating downstream infections when other developers clone or consume the altered code. The campaign has also used sleeper or impersonation extensions that appear benign at publication time and are weaponized later through updates, dependency chains, or thin-loader behavior that retrieves payloads externally.
GlassWorm used a resilient multi-channel command-and-control architecture designed to survive partial disruption. Reported channels included blockchain-based dead drops, BitTorrent DHT, Google Calendar, and conventional VPS-hosted infrastructure. In May 2026, a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation disrupted all known command-and-control channels simultaneously, severing operator access to infected hosts and preventing delivery of new payloads through those channels.
The campaign has been described as likely operated by Russian-speaking cybercriminals based on geofencing behavior and Russian-language comments in malware code, although those indicators are not independently conclusive. GlassWorm is widely associated with broader developer-focused supply-chain activity that also overlaps with campaigns such as Shai-Hulud and TeamPCP-linked operations, but direct attribution beyond the reported likelihood of Russian-speaking operators remains limited.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These investigations have identified a central figure known online as "ResoluteXBF" with connections to South African-based infrastructure. Even though the group was relatively new when it emerged in 2010, it has rapidly evolved from the Shai-Hulud campaign to subsequent operations that involved malware such as GlassWorm...
A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections
Within a short period of time, the threat actor compromised more than 1,000 software packages and weaponized trusted development channels... Through compromise of CI runners, TeamPCP effectively converted trusted software distribution channels into malware delivery channels... downstream developers were able to retrieve them using package managers, GitHub Actions, Python libraries, NPM registries, and other software components that were configured to pull the latest releases from the repository.
Trojanized VSCode extensions were published to the OpenVSX marketplace, disguised as popular tools like time trackers and code formatters.
It then force-pushed malicious commits to every repository the victim’s account could reach, spreading the infection to any developer who later cloned those repositories.
File i.js JavaScript payload file written to script directory during execution
The next month, researchers discovered the Glassworm attack, which utilizes VS Code extensions to compromise developer machines.
It used invisible Unicode characters to hide malicious logic inside extension source files, making the code appear as empty lines to human reviewers and automated tools alike.
The campaign we analyzed, however, uses a different and under-observed class of characters (variation selectors) that remain largely invisible to common tooling.
The injection preserves the original commit author and date, making it look like nothing in the project history has changed.
More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections
The next month, researchers discovered the Glassworm attack, which utilizes VS Code extensions to compromise developer machines.
Before doing anything visible, the malware validates the environment. It checks locale settings and will exit early on systems configured with Russian-language locales... It also probes for EDR software: CrowdStrike Falcon, SentinelOne, Carbon Black, and the StepSecurity Harden-Runner for GitHub Actions are all specifically detected.
Once active, GlassWorm harvested GitHub tokens, npm tokens, OpenVSX tokens, and cryptocurrency wallet data.
Glassworm steals GitHub tokens from multiple sources, including VS Code storage, the git credentials file, and local environment variables.
The malware checks the victim's locale, language settings, and timezone at runtime
Before doing anything visible, the malware validates the environment. It checks locale settings and will exit early on systems configured with Russian-language locales... It also probes for EDR software: CrowdStrike Falcon, SentinelOne, Carbon Black, and the StepSecurity Harden-Runner for GitHub Actions are all specifically detected.
CrowdStrike, together with Google and the Shadowserver Foundation, neutralized all four GlassWorm command-and-control channels on May 26, 2026.
Glassworm used invisible Unicode-based code injection, blockchain-based C2 infrastructure, and Google Calendar as a backup command server to turn infected developers’ machines into criminal proxy nodes.
It also used Google Calendar event titles as dead-drop locations for Base64-encoded C2 paths.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
96 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows malware referenced for comparison that detected USB device insertion and displayed its own malicious wallet-related window after terminating the legitimate application.
Referenced as another supply-chain campaign known for locale-based execution gating, specifically exiting on Russian-language locales.
GlassWorm spread via malicious VS Code/OpenVSX extensions, hid code with invisible Unicode characters, harvested developer and crypto-related tokens/data, and force-pushed malicious commits to accessible repositories to propagate further.
Named malware involved in subsequent TeamPCP operations after the Shai-Hulud campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.