Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A Russia-linked threat group operating the Glassworm botnet spent over a year systematically compromising software developers by distributing malicious code extensions, poisoned open-source packages, and harvesting credentials from developer repositories. The campaign targeted the software supply chain directly, using developer workstations and CI/CD pipelines as entry points into downstream organizations. Organizations whose development teams use VSCode-compatible editors, npm, or PyPI packages face elevated risk of upstream code compromise, credential theft, and potential backdoors embedded in internally developed software.

Author

Tech Jacks Solutions