Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A Russia-linked threat group operating the Glassworm botnet spent over a year systematically compromising software developers by distributing malicious code extensions, poisoned open-source packages, and harvesting credentials from developer repositories. The campaign targeted the software supply chain directly, using developer workstations and CI/CD pipelines as entry points into downstream organizations. Organizations whose development teams use VSCode-compatible editors, npm, or PyPI packages face elevated risk of upstream code compromise, credential theft, and potential backdoors embedded in internally developed software.

Author

Tech Jacks Solutions