Apps & Consumer
CrowdStrike and Google dismantle Glassworm botnet
CrowdStrike, Google, and Shadowserver dismantled the Glassworm botnet, which spent two years poisoning more than 300 GitHub repositories to target open source software developers.
Cybersecurity firm CrowdStrike, working in collaboration with Google and Shadowserver, a nonprofit internet security monitor, has dismantled the Glassworm botnet—a network of infected computers used by cybercriminals to push malware and steal passwords. According to CrowdStrike, the Glassworm hackers spent two years targeting the broader open source software supply chain. The joint operation successfully neutralized four command-and-control channels, which are servers used to manage the botnet. Neutralizing these channels cut the hackers’ access to infected computers and stopped them from delivering further malicious software.
To execute the campaign, the Glassworm hackers relied on multiple methods to distribute their malicious software. These tactics included publishing malicious extensions on developer marketplaces, stealing credentials, and utilizing malvertising—a technique where hackers pay for malicious advertising in sponsored search results to trick users into downloading malware. By leveraging credentials stolen in previous breaches, the cybercriminals hijacked developer accounts to plant malicious software directly into active projects. Through these methods, the hackers were able to poison more than 300 GitHub code repositories, exploiting the trust that companies place in code hosted on the platform.
This activity highlights a significant tactical shift among cybercriminals, who are increasingly focusing on the creators of software rather than the finished products themselves. In its report on the operation, CrowdStrike wrote: “Adversaries are no longer just targeting products, they’re targeting the developers who build them,” explaining that developers represent uniquely high-value targets because compromising a single workstation can cascade into a supply-chain compromise—a security breach affecting downstream users—that impacts thousands of downstream organizations and users.
The disruption of Glassworm occurs alongside a broader surge in cyberattacks aimed at the developer ecosystem. Last week, a separate hacking campaign compromised several open source projects, which included targeting OpenAI. Additionally, in March, a separate supply chain attack hijacked Axios, a software development tool used by developers to build applications. It remains unclear under what legal or technical authority CrowdStrike and its partners operated to execute the takedown, as a spokesperson for the cybersecurity firm declined to comment on the details of the operation.
Why it matters
The operation highlights a shift in cybercriminal strategy: rather than attacking end-products, adversaries are increasingly targeting the developers themselves to compromise the entire software supply chain. By poisoning open source repositories, hackers can exploit downstream trust to compromise thousands of organizations at once.