GlassWorm is a self-propagating, credential-stealing software supply-chain worm targeting software developers and their development environments. First identified in 2025, it has been distributed through trojanized Visual Studio Code extensions, compromised npm and Python packages, and poisoned source-code repositories. The campaign targets VS Code and several VS Code-derived IDEs, exploiting developer access to source repositories, package registries, cloud platforms, CI/CD systems, and cryptocurrency wallets.
GlassWorm uses concealed code, including invisible Unicode characters, to hinder review of malicious extension code. It harvests developer credentials and tokens, browser data and session material, cloud and package-registry access, SSH material, and cryptocurrency wallet data. Stolen credentials have been used to force-push malicious commits into repositories accessible to victims, enabling further propagation to downstream developers. The malware also deploys GlassWormRAT, a JavaScript-based remote access tool capable of arbitrary command execution and browser-data theft. Associated components can install a malicious browser extension for keystroke logging, clipboard collection, screenshot capture, and session-data collection, and can repurpose compromised hosts as SOCKS proxies, hidden VNC systems, and remote-execution nodes.
GlassWorm employs layered and resilient command-and-control mechanisms, including Solana transaction memos, BitTorrent DHT lookups, Google Calendar event titles, and conventional hosted infrastructure. It uses environment checks, including locale, language, and timezone filtering that excludes CIS-oriented systems, and hidden VNC to reduce victim visibility. A coordinated operation in May 2026 disrupted its known command-and-control channels. The operators have been assessed as likely Russia-based or Russian-speaking cybercriminals; this assessment is based on CIS avoidance logic and Russian-language code comments, neither of which is independently conclusive.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These investigations have identified a central figure known online as "ResoluteXBF" with connections to South African-based infrastructure. Even though the group was relatively new when it emerged in 2010, it has rapidly evolved from the Shai-Hulud campaign to subsequent operations that involved malware such as GlassWorm...
A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections
Within a short period of time, the threat actor compromised more than 1,000 software packages and weaponized trusted development channels... Through compromise of CI runners, TeamPCP effectively converted trusted software distribution channels into malware delivery channels... downstream developers were able to retrieve them using package managers, GitHub Actions, Python libraries, NPM registries, and other software components that were configured to pull the latest releases from the repository.
Trojanized VSCode extensions were published to the OpenVSX marketplace, disguised as popular tools like time trackers and code formatters.
It then force-pushed malicious commits to every repository the victim’s account could reach, spreading the infection to any developer who later cloned those repositories.
File i.js JavaScript payload file written to script directory during execution
It used invisible Unicode characters to hide malicious logic inside extension source files, making the code appear as empty lines to human reviewers and automated tools alike.
The campaign we analyzed, however, uses a different and under-observed class of characters (variation selectors) that remain largely invisible to common tooling.
The injection preserves the original commit author and date, making it look like nothing in the project history has changed.
More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections
The next month, researchers discovered the Glassworm attack, which utilizes VS Code extensions to compromise developer machines.
Before doing anything visible, the malware validates the environment. It checks locale settings and will exit early on systems configured with Russian-language locales... It also probes for EDR software: CrowdStrike Falcon, SentinelOne, Carbon Black, and the StepSecurity Harden-Runner for GitHub Actions are all specifically detected.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Once active, GlassWorm harvested GitHub tokens, npm tokens, OpenVSX tokens, and cryptocurrency wallet data.
Glassworm ... is a self-propagating, credential-stealing worm ... later poisoned more than 300 GitHub repos using stolen credentials harvested in earlier Glassworm infections.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Glassworm steals GitHub tokens from multiple sources, including VS Code storage, the git credentials file, and local environment variables.
The malware checks the victim's locale, language settings, and timezone at runtime
Before doing anything visible, the malware validates the environment. It checks locale settings and will exit early on systems configured with Russian-language locales... It also probes for EDR software: CrowdStrike Falcon, SentinelOne, Carbon Black, and the StepSecurity Harden-Runner for GitHub Actions are all specifically detected.
CrowdStrike, together with Google and the Shadowserver Foundation, neutralized all four GlassWorm command-and-control channels on May 26, 2026.
Glassworm used invisible Unicode-based code injection, blockchain-based C2 infrastructure, and Google Calendar as a backup command server to turn infected developers’ machines into criminal proxy nodes.
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
It also used Google Calendar event titles as dead-drop locations for Base64-encoded C2 paths.
Direct server connections : Traditional C2 infrastructure hosted on commercial VPS providers served as the final payload delivery mechanism.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
103 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign referenced as illustrating attacks against registries and marketplaces via developer tooling and package ecosystems.
Self-propagating malware that uses Solana transaction metadata as a dead drop resolver, querying recent wallet transactions and decoding memo data to recover a Base64-encoded C2 URL.
A stealer distributed through malicious IDE extensions that installs a secondary malicious extension, exfiltrates crypto wallet data, environment variables, and other secrets, and installs a RAT on infected devices.
Mentioned only as a prior malware example that used the Ethereum blockchain to retrieve command-and-control server addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.