Glassworm is a malware family tracked across 24 threat clusters and 64 intelligence report mentions on ThreatCluster. First observed November 2, 2025; most recent activity July 23, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
On March 16, 2026, two React Native npm packages, [email protected] and [email protected], were compromised in a supply chain attack attributed to Glassworm malware. The…
A resurgence of the GlassWorm malware campaign has been identified, targeting the OpenVSX ecosystem with 73 'sleeper' extensions that become malicious after updates. Six of these extensions have already been activated…
A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants,…
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
The ForceMemo campaign, attributed to the GlassWorm threat actor, is actively targeting the Python open-source ecosystem by exploiting stolen GitHub tokens to inject obfuscated malware into numerous repositories. The…
A variant of the GlassWorm malware has been identified, distributed through a compromised Cursor extension on Open VSX. The attack utilizes a sophisticated infection chain and a resilient command-and-control (C2)…
The GlassWorm malware campaign has intensified its operations by utilizing 72 newly identified malicious Open VSX extensions. These extensions exploit transitive dependencies within developer environments, allowing the…
The GlassWorm malware campaign has been identified, using hidden Unicode characters to embed malicious code within open-source software components. Researchers discovered this threat in early March 2026, tracing…
A malicious extension named code-wakatime-activity-tracker has been identified on the OpenVSX marketplace, designed to spread the GlassWorm malware across multiple integrated development environments (IDEs) including VS…