Trojan Source - Vulnerability

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
March 21, 2026
Last Seen
March 21, 2026

Trojan Source is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

Trojan Source is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed March 21, 2026; most recent activity March 21, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • GlassWorm malware hides in invisible open-source code — Aol · March 21, 2026
  • GlassWorm malware hides in invisible open-source code — Scientificamerican · March 21, 2026

Frequently asked questions

What is Trojan Source?

Trojan Source is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

Is Trojan Source still active?

The most recent intelligence report mentioning Trojan Source on ThreatCluster is dated March 21, 2026.

What is Trojan Source associated with?

Across ThreatCluster reporting, Trojan Source most frequently co-occurs with Supply Chain Attack, Glassworm, T1195 - Supply Chain Compromise, GitHub, Npm.

What are the latest developments involving Trojan Source?

The most significant recent cluster is “GlassWorm Malware Exploits Invisible Code in Open-Source Software” (2 articles · Updated March 21, 2026). Trojan Source appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Trojan Source?

Trojan Source appears in 2 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown