GlassWorm Malware Exploits Invisible Code in Open-Source Software
Article Content
- •GlassWorm malware hides in invisible Unicode characters in open-source code.
- •Hundreds of compromised packages were found across major developer platforms.
- •The attack exploits software dependency structures, affecting multiple programming languages.
The GlassWorm malware campaign has been identified, using hidden Unicode characters to embed malicious code within open-source software components. Researchers discovered this threat in early March 2026, tracing hundreds of compromised packages across platforms like GitHub and npm. The attack undermines trust in software development by exploiting the assumption that visible code is safe. Justin Cappos, a computer science professor, compares the attack to a typewriter hiding messages in plain sight. The campaign builds on previous vulnerabilities like the Trojan Source attack identified in 2021. The recent wave of attacks was notable for its scale and sophistication, affecting JavaScript, TypeScript, and Python repositories. Cybersecurity firms Aikido, StepSecurity, and Socket reported extensive activity during the first week of March. The ongoing threat emphasizes the need for improved scrutiny of open-source contributions. As of now, the campaign remains active and poses significant risks to software supply chains.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Glassworm in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PEEP Chrome Extension Turns Browsers Into Remote Access Tools Cybersecurity researchers have uncovered a sophisticated post-exploitation toolkit named PEEP, which masquerades as a 'Smart Bookmarks' Chrome extension. This malware requires prior administrative access to be installed, allowing it to bypass Web Store checks and inject itself directly into Chrome and Edge profiles.…