CrowdStrike, Google disrupt GlassWorm developer supply-chain botnet (opens in new tab)
CrowdStrike said it worked with Google and the Shadowserver Foundation to disrupt GlassWorm, a self-propagating, credential-stealing botnet that targeted software developers through malicious packages and extensions in the open-source software supply chain. The campaign targeted developers since at least early 2025 and poisoned more than 300 GitHub repositories, creating risk of broader software supply-chain compromise. The operation cut off four command-and-control channels at the same time,...
Read the original article