Cybersecurity — 2026-05-27

CrowdStrike Google and Shadowserver Take Down Glassworm Botnet Targeting Software Developers in Supply Chain Attacks

BLUFDespite the coordinated takedown, public attribution of resumed Glassworm command-and-control to the same Russia-linked operators is unlikely before August 24, 2026, leaving compromised credentials and poisoned dependencies as the immediate enterprise risk.

On May 26, CrowdStrike's Counter Adversary Operations team, in coordination with Google and the Shadowserver Foundation, simultaneously disrupted all four command-and-control channels of the Glassworm botnet, severing operators from infected developer machines 123. Active since at least early 2025, the campaign spread through trojanized VSCode extensions on the OpenVSX marketplace, malicious npm and Python packages, and stolen developer credentials used to poison more than 300 GitHub repositories 124. The four C2 channels relied on the Solana blockchain, the BitTorrent DHT network, Google Calendar event titles, and commercial VPS servers as successive resolution layers 124. CrowdStrike assessed the operators as likely Russia-based, citing CIS-country locale checks embedded in the malware and Russian-language comments throughout the source code 14.

Analysis
The C2 takedown ends operator access but leaves every organization that installed poisoned npm, PyPI, or OpenVSX dependencies with active remediation exposure; harvested credentials and tokens remain valid attack surfaces until rotated. Russia attribution rests solely on CrowdStrike's own technical reporting; no government, law enforcement, or independent technical source has corroborated it, and the four-channel resilience architecture fits state-sponsored development cycles more than independent criminal operations. Resumed Glassworm C2 activity attributed to the same operators is unlikely before August 24, 2026. Moderate confidence reflects the simultaneous neutralization of all four resilience layers and the steep operational cost of rebuilding that architecture without exposing new infrastructure to the monitoring posture that enabled the original takedown. If a major vendor attributes resumed activity before that date, security teams must sustain active incident response; absent that signal, resources shift to repository remediation.
4 sources
  1. Disrupting Glassworm: Inside CrowdStrike's Takedown of a Developer-Targeting Botnet
  2. CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks - TechCrunch
  3. Coordinated operation takes down Glassworm botnet - Cybersecurity Dive
  4. GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE