GlassWorm Expands to 433 Repos Across GitHub, npm, and VSCode

1 min read
Source: BleepingComputer
GlassWorm Expands to 433 Repos Across GitHub, npm, and VSCode
Photo: BleepingComputer
TL;DR Summary

A renewed GlassWorm supply-chain campaign has compromised 433 components across GitHub, npm, and VSCode/OpenVSX, spreading via compromised accounts, obfuscated code, and a Solana-based C2 to harvest wallet data, credentials, and environment info; indicators include marker lzcdrtfxyqiplpd and init.json persistence, with warnings to inspect for rogue Node.js installs and unusual commit histories.

Share this article

Reading Insights

Total Reads

0

Unique Readers

2

Time Saved

4 min

vs 5 min read

Condensed

94%

83651 words

Want the full story? Read the original article

Read on BleepingComputer