GlassWorm — Malware Profile
GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems. GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult. GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain. GlassWorm was first reported in October 2025.
MITRE ATT&CK techniques (36)
- T1005 Data from Local System
- T1008 Fallback Channels
- T1027.013 Encrypted/Encoded File
- T1027.018 Invisible Unicode
- T1036 Masquerading
- T1059.002 AppleScript
- T1059.007 JavaScript
- T1071.001 Web Protocols
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1090.001 Internal Proxy
- T1102.001 Dead Drop Resolver
- T1105 Ingress Tool Transfer
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1195.001 Compromise Software Dependencies and Development Tools
- T1213.003 Code Repositories
- T1213.006 Databases
- T1217 Browser Information Discovery
- T1480 Execution Guardrails
- T1518 Software Discovery
- T1539 Steal Web Session Cookie
- T1543.001 Launch Agent
- T1547.001 Registry Run Keys / Startup Folder
- T1554 Compromise Host Software Binary
- T1555.001 Keychain
- T1555.003 Credentials from Web Browsers
- T1560.001 Archive via Utility
- T1564.003 Hidden Window
- T1565.002 Transmitted Data Manipulation
- T1571 Non-Standard Port
- T1602.002 Network Device Configuration Dump
- T1614 System Location Discovery
- T1614.001 System Language Discovery
- T1657 Financial Theft
- T1678 Delay Execution
IntelFusions coverage
- Glassworm: Invisible Unicode Malware Hits 151+ GitHub Repos, npm, and VS Code in Coordinated Supply Chain Campaign 2026-03-17
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10
- Shai-Hulud supply chain worm evolves to fool AI security scanners 2026-06-14
- Opening a Malicious Repo Could Hijack Amazon Q in VS Code 2026-06-27