GlassWorm Malware Exploits Invisible Code in Open-Source Software

GlassWorm Malware Exploits Invisible Code in Open-Source Software

First seen 21 Mar 2026, 23:27 UTC ScientificamericanAol 97% similarity 66.0

Article Content

Browse articles
ThreatCluster

The GlassWorm malware campaign has been identified, using hidden Unicode characters to embed malicious code within open-source software components. Researchers discovered this threat in early March 2026, tracing hundreds of compromised packages across platforms like GitHub and npm. The attack undermines trust in software development by exploiting the assumption that visible code is safe. Justin Cappos, a computer science professor, compares the attack to a typewriter hiding messages in plain sight. The campaign builds on previous vulnerabilities like the Trojan Source attack identified in 2021. The recent wave of attacks was notable for its scale and sophistication, affecting JavaScript, TypeScript, and Python repositories. Cybersecurity firms Aikido, StepSecurity, and Socket reported extensive activity during the first week of March. The ongoing threat emphasizes the need for improved scrutiny of open-source contributions. As of now, the campaign remains active and poses significant risks to software supply chains.

Key Points: • GlassWorm malware hides in invisible Unicode characters in open-source code. • Hundreds of compromised packages were found across major developer platforms. • The attack exploits software dependency structures, affecting multiple programming languages.

ThreatCluster AI

Timeline

2026-03-03
Researchers began investigating GlassWorm malware.
2026-03-09
Cybersecurity firms traced GlassWorm activity across repositories.
2026-03-21
Articles published detailing the GlassWorm campaign.

Community

Browse all →