CrowdStrike and Google Dismantle Glassworm Botnet That Poisoned Hundreds of Open Source Repositories

CrowdStrike, Google, and nonprofit Shadowserver took down the Glassworm botnet in May 2026, dismantling an operation that cybercriminals had used for two years to inject malware into open source software and compromise the developers and organizations that rely on it.

The takedown severed four command-and-control channels that the Glassworm hackers used to maintain access to infected machines and deliver additional malware. Those channels operated across the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers.

Over the course of the campaign, the hackers poisoned more than 300 GitHub code repositories. They used multiple methods to spread their malicious code: publishing malicious extensions on developer marketplaces, running malvertising campaigns through sponsored search results, and using previously stolen credentials to hijack developer accounts and plant malware directly in their projects.

“Adversaries are no longer just targeting products, they’re targeting the developers who build them,” CrowdStrike wrote in its report. “Compromising a single developer’s workstation can cascade into a supply-chain compromise that impacts thousands of downstream organizations and users.”

The authority under which CrowdStrike and its partners operated to execute the takedown has not been disclosed. A CrowdStrike spokesperson did not immediately comment on the legal or technical basis for the action.

The Glassworm disruption comes amid a broader wave of supply chain attacks targeting open source software. Last week, a separate campaign called “Mini Shai-Hulud” compromised several open source projects and affected at least one OpenAI developer. In March, a suspected North Korean hacker hijacked the widely used open source tool Axios, which is used by millions of developers.

These incidents highlight a growing pattern in which attackers exploit the trust developers and companies place in shared code hosted on platforms like GitHub, potentially turning a single compromised project into a wide-reaching threat.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top