GlassWorm attack installs fake browser extension for surveillance

GlassWorm is a sophisticated malware targeting developers through compromised code repositories and package managers. It executes in stages, starting with a stealthy infection that fingerprints the machine and fetches further payloads via the Solana blockchain. The malware steals sensitive data, including cryptocurrency wallets and development credentials, installs a Remote Access Trojan (RAT), and deploys a fake Chrome extension for extensive surveillance. It uses distributed hash tables and blockchain for resilient command and control. While initially focused on developers with potential cryptocurrency assets, the stolen information could enable wider supply chain attacks. Prevention strategies include careful package management, regular extension audits, and up-to-date anti-malware solutions.

Pulse ID: 69c59ad1d050c7b6a823051e
Pulse Link: https://otx.alienvault.com/pulse/69c59ad1d050c7b6a823051e
Pulse Author: AlienVault
Created: 2026-03-26 20:45:05

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BlockChain #Browser #Chrome #ChromeExtension #CyberSecurity #FakeBrowser #InfoSec #Mac #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SupplyChain #Trojan #Worm #bot #cryptocurrency #developers #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Cryptocurrency reaches retirement accounts of Americans | Currency Pair Analysis

Professional traders know the value of timely analysis. Enjoy this expert forex review. While
Bitcoin and Ethereum have been losing ground, news yesterday revealed that a
rulemakin

https://www.robotfx.org/2026/03/cryptocurrency-reaches-retirement.html

#Cryptocurrency #Reaches #Retirement #Robotfx

Cryptocurrency reaches retirement accounts of Americans | Currency Pair Analysis

Professional traders know the value of timely analysis. Enjoy this expert forex review. While Bitcoin and Ethereum have been losing ground, ...

RobotFX

Live: ASX to drop, following sea of red on Wall St
By Adelaide Miller

The ASX is set to fall at the open, following a sea of red on Wall Street. Follow the day's events and insights from our business reporters on the ABC News live markets blog.

https://www.abc.net.au/news/2026-03-27/asx-markets-business-news-live-updates-friday-march-27/106500898

#StockMarket #FinancialMarkets #Currency #CompanyNews #BusinessEconomicsandFinance #EconomicTrendsandIndicators #Cryptocurrency #AdelaideMiller

Live: ASX to drop, following sea of red on Wall St

The ASX is set to fall at the open, following a sea of red on Wall Street. Follow the day's events and insights from our business reporters on the ABC News live markets blog. 

I invest 500$ in Crypto - BOCVIP

Hello guys I have 600$ on My wallet and I am thinking that to buy coins in this 2026 crash 100$ of xrp 100$ of ChainLink and 2 3 coin solana ETH AND BTC also

BOCVIP

We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases.
So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams.

Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and device-based filters. They stack bulletproof hosting and reverse proxies to add layers of indirection, making takedown and analysis harder. In this post, we share how we overcame this using multi‑protocol, multi‑vantage telemetry. We leveraged JA4+ web server fingerprints, DNS analytics, and Confiant’s visibility into advertising supply chain data to uncover Keitaro abuse and the delivery of malware downloaders, infostealers, weaponized RMMs, wallet drainer campaigns, scams, and email spam and advertising attack vectors.

If you hunt threats distributed via adtech, these indicators can be useful pivots. https://www.infoblox.com/blog/threat-intelligence/no-reach-no-risk-the-keitaro-abuse-in-modern-cybercrime-distribution/

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising #infostealer #rmm #remotemonitoringmanagement #downloader #malware #spam #airdrop #cryptocurrency #ja4 #ja4_fingerprinting