GlassWorm conducted a renewed software supply-chain campaign that compromised open-source components across GitHub, npm, VSCode, and OpenVSX, with researchers attributing at least 433 malicious repositories, packages, and extensions to the operation. Reporting from multiple security firms linked the activity through shared infrastructure, similar payloads, and the same Solana blockchain address used for command-and-control. The campaign reportedly began with compromised GitHub accounts and force-pushed malicious commits, then expanded into published npm packages and editor extensions containing obfuscated code designed to evade review and steal developer credentials, cryptocurrency wallet data, and other sensitive information.
One documented part of the campaign involved the backdooring of the npm packages react-native-country-select@0.3.91 and react-native-international-phone-number@0.11.8, both published by AstrOOnauta and together downloaded more than 134,000 times in the prior month. Aikido found both packages used a new preinstall hook to execute an obfuscated install.js loader during a routine npm install, allowing infection of developer workstations, CI runners, and build agents without additional user action. Researchers said the loader was byte-identical in both packages, indicating deliberate tampering rather than a build error, and placed the incident within GlassWorm's broader pattern of using stealthy package modifications and cross-platform malware delivery to target the software development ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Aikido reported a trojanized OpenVSX extension, code-wakatime-activity-tracker, impersonating WakaTime and loading a Zig-compiled native Node.js addon to run outside the JavaScript sandbox. The binary enumerated installed VS Code-compatible editors and silently installed a second-stage malicious VSIX across VS Code, Cursor, Windsurf, VSCodium, and Positron from an attacker-controlled GitHub Releases page.
On 2026-04-01, Breakglass Intelligence reported that GlassWorm Wave 3 used a Solana wallet as a dead-drop to publish command-and-control servers, allowing researchers to reconstruct seven sequential C2 rotations spanning 2025-12-17 to 2026-03-31. The report also said the current C2 and a separate exfiltration server were still live, with signs the operator actively monitored probing attempts in real time.
Researchers reported GlassWorm had expanded into the MCP ecosystem through npm packages impersonating a WaterCrawl MCP server. The activity marked a new extension of the campaign beyond previously documented package and IDE extension compromises in developer ecosystems.
Bitdefender discovered a malicious Windsurf IDE extension impersonating an R programming support tool to steal passwords, session cookies, and other developer secrets. The extension used Solana blockchain transactions to retrieve encrypted JavaScript, avoided Russian time zones, and established persistence with a hidden PowerShell scheduled task named UpdateApp.
Aikido published technical analysis showing GlassWorm uses Solana memo fields for stage delivery, steals developer and wallet data, and deploys a persistent WebSocket-based RAT. The report also described a malicious Chrome extension disguised as Google Docs Offline that performs keylogging, cookie theft, screenshots, clipboard capture, and targeted monitoring of Bybit session cookies.
Breakglass Intelligence reported Wave 3 GlassWorm tooling that expanded the campaign into a cross-platform cryptocurrency theft operation, including a macOS Rust sideloader that installs a fake Google Docs Offline Chrome extension and a Windows DLL targeting six Chromium-based browsers. The report said the Windows component could bypass Chrome 127+ App-Bound Encryption using Chrome's COM elevation interface and that both platforms retrieved C2 settings from Solana transaction memo fields.
Researchers reported a coordinated GlassWorm supply-chain wave affecting GitHub, npm, and VSCode/OpenVSX, with 433 compromised components identified within a single month. The campaign used compromised GitHub accounts, force-pushed malicious commits, and obfuscated code to spread credential- and wallet-stealing malware across developer ecosystems.
On March 16, 2026, two popular React Native packages, react-native-country-select@0.3.91 and react-native-international-phone-number@0.11.8, were published with malicious GlassWorm code. The packages executed automatically during npm install via a preinstall hook and delivered a multi-stage Windows-focused stealer targeting wallet data, npm tokens, and GitHub credentials.
On 2026-03-16, Breakglass Intelligence reported that a malicious Node.js dropper targeting Solana and crypto developers used Solana transaction memos as a dead-drop resolver for rotating C2 servers. The researchers attributed the activity with high confidence to Lazarus Group's TraderTraitor sub-cluster and said the infrastructure had operated from November 2025 through March 2026 across seven rotating VPS nodes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
rhisac.org
Open sourceandrii.ro
Open sourceaikido.dev
Open sourceintel.breakglass.tech
Open sourcecybersecuritynews.com
Open sourceintel.breakglass.tech
Open sourcebleepingcomputer.com
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.