GlassWorm
According to Koi Security, this malware harvests NPM, GitHub, and Git credentials for supply chain propagation. It targets 49 different cryptocurrency wallet extensions to drain funds. It uses stolen credentials to compromise additional packages and extensions, spreading the worm further. Furthermore, it deploys SOCKS proxy servers, turning developer machines into criminal infrastructure and installs hidden VNC servers for complete remote access.
C2 Infrastructure
Hosting/VPS100%
Last 7 days
Apr 24, 2026
C2 Hosts: 1
| Date | C2 Hosts |
|---|---|
| Apr 24, 2026 | 1 |