Cybersecurity & Privacy — 2026-03-18

GlassWorm Supply-Chain Campaign Compromises 433 GitHub, npm, and VSCode Components

The GlassWorm supply-chain campaign returned with 433 compromised components across GitHub (200 Python repos, 151 JS/TS repos), 72 VS Code extensions, and 10 npm packages. Payloads are encoded in invisible PUA Unicode characters (U+FE00-U+FE0F range), rendering them invisible in all mainstream editors and code review tools. The malware uses Solana blockchain queries every 5 seconds for C2 instructions, targeting crypto wallets, SSH keys, and developer credentials.

View in full brief →

UNCLASSIFIED // OPEN SOURCE