Glassworm developer supply-chain infection to redundant multi-resolver C2
Glassworm
IIM chain for Glassworm as documented by CrowdStrike on 2026-05-26: the operators targeted developers through OpenVSX/VS Code-style extensions, npm and Python packages, and poisoned GitHub repositories. The installed malware delivered Glassworm downloader/RAT capability and resolved operational endpoints through four resilient C2 channels: Solana transaction memo dead-drops, BitTorrent DHT configuration lookup, Google Calendar event-title dead-drops, and direct commercial VPS C2 servers. CrowdStrike, Google and Shadowserver disrupted the channels simultaneously. Exact malicious package names and original VPS C2 addresses were not published in the source article; this chain models the confirmed infrastructure architecture without inventing unpublished IoCs.
entry · file · Trojanized VS Code / OpenVSX extension package · IIM-T006entry · file · Compromised npm package with postinstall hook · IIM-T006entry · file · Compromised Python package with setup script · IIM-T006entry · url · github://poisoned-default-branches/more-than-300-repositories · IIM-T006