CrowdStrike and Google Disrupt Botnet Aimed at Software Developers in Supply Chain Attacks
In partnership with Google and Shadowserver, a nonprofit dedicated to scanning and overseeing the internet for cyber threats, CrowdStrike has disrupted a botnet leveraged by cybercriminals to spread malware and steal passwords from open-source software developers.
The goal of this takedown initiative was to hinder the operations of the perpetrators behind the Glassworm botnet, who have been focusing on the open-source software supply chain for the last two years, as reported by CrowdStrike.
Recently, various hacking factions have increasingly targeted developers and open-source initiatives to propagate harmful software to companies and organizations that rely on such platforms. These attacks exploit the trust that companies have in code available on sites like GitHub and in the developers behind it.
“Adversaries are shifting their focus from merely products to the developers who create them,” CrowdStrike observed in its report concerning the takedown. “Developers represent exceptionally high-value targets: compromising a single developer’s environment can lead to a supply-chain compromise impacting thousands of downstream entities and users.”
The hackers associated with Glassworm employed various methods to spread their malicious software. These included publishing harmful extensions on developer-frequented marketplaces, utilizing malvertising—where attackers pay for misleading promoted search results enticing victims to download malware—and using stolen credentials from previous breaches to commandeer developer accounts and insert malware into their projects.
Ultimately, the hackers managed to infect— as described by CrowdStrike—over 300 GitHub code repositories.
Contact Us
If you have additional information regarding the Glassworm hacking group or other supply chain incidents, please contact Lorenzo Franceschi-Bicchierai securely via Signal at +1 917 257 1382, or on Telegram, Keybase, and Wire @lorenzofb, or by email.
CrowdStrike announced that it successfully dismantled four command-and-control servers used by the Glassworm hackers, effectively cutting off their access to infected machines and stopping further malware distribution.
The command-and-control servers utilized platforms like the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers, according to CrowdStrike.
The specifics regarding the legal or technical authority permitting CrowdStrike and its allies to engage in the takedown remain uncertain. A spokesperson for CrowdStrike has not offered any immediate comments.
In a separate hacking incident last week, several open-source projects were compromised in an operation labeled “Mini Shai-Hulud,” leading to the release of malicious updates. An OpenAI developer fell victim to this attack group. Additionally, a suspected North Korean hacker took control of the widely-used open-source development tool Axios in a March supply chain breach, impacting millions of developers.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


