GlassWorm Malware hits 400+ Code Repos on GitHub, npm, VSCode and OpenVSX to target Developers.
Researchers at Aikido, Socket, Step Security, and the OpenSourceMalware community have collectively identified 433 compromised components this month in attacks attributed to GlassWorm.
⁉️Evidence of a single threat actor running the GlassWorm campaigns across multiple open-source repositories is provided by the use of the same Solana blockchain address used for command-and-control [C2] activity, identical or functionally similar payloads, and shared infrastructure.⁉️
https://www.aikido.dev/blog/glassworm-returns-unicode-attack-github-npm-vscode
#github #npm #vscode #unicode #attack #secure #programming #media #developer #security #privacy #tech #news







