Skip to content
GlassWorm Malware Exploits Invisible Code in Open-Source Software

GlassWorm Malware Exploits Invisible Code in Open-Source Software

First seen 21 Mar 2026, 23:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 22, 2026 at 22:28 UTC
  • GlassWorm malware hides in invisible Unicode characters in open-source code.
  • Hundreds of compromised packages were found across major developer platforms.
  • The attack exploits software dependency structures, affecting multiple programming languages.

The GlassWorm malware campaign has been identified, using hidden Unicode characters to embed malicious code within open-source software components. Researchers discovered this threat in early March 2026, tracing hundreds of compromised packages across platforms like GitHub and npm. The attack undermines trust in software development by exploiting the assumption that visible code is safe. Justin Cappos, a computer science professor, compares the attack to a typewriter hiding messages in plain sight. The campaign builds on previous vulnerabilities like the Trojan Source attack identified in 2021. The recent wave of attacks was notable for its scale and sophistication, affecting JavaScript, TypeScript, and Python repositories. Cybersecurity firms Aikido, StepSecurity, and Socket reported extensive activity during the first week of March. The ongoing threat emphasizes the need for improved scrutiny of open-source contributions. As of now, the campaign remains active and poses significant risks to software supply chains.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 181d ago How this analysis works

Timeline

2026-03-03
Researchers began investigating GlassWorm malware.
2026-03-09
Cybersecurity firms traced GlassWorm activity across repositories.
2026-03-21
Articles published detailing the GlassWorm campaign.

More articles in this cluster (2)

Following this threat?

Track Glassworm in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed