Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CrowdStrike, Google, and the Shadowserver Foundation dismantled Glassworm, a botnet that targeted software developers by distributing malware through compromised GitHub repositories, malicious IDE extensions for Cursor, Positron, Windsurf, and VSCodium, and trojanized npm and Python packages. The campaign ran across Windows, macOS, and Linux, using four separate command-and-control channels to maintain resilience. The strategic objective was downstream access, compromising developer infrastructure to reach the organizations and end users those developers build for, making every application in an affected pipeline a potential victim.

Author

Tech Jacks Solutions