Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1922 articles · 155850 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED

Glassworm Botnet Takedown Targeting Software Developers

60% confidence

Description

The Glassworm botnet, targeting software developers through open-source supply chain compromises, was coordinated by CrowdStrike, Google, and the Shadowserver Foundation. It used trojanized VSCode extensions, compromised npm/Python packages, and poisoned GitHub repositories to execute malicious payloads. The botnet's C2 infrastructure leveraged blockchain, BitTorrent DHT, Google Calendar, and VPS servers for resilience.

Related News (1 articles)

Tier C
CrowdStrike Blog14h ago
Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedMay 26, 2026
Last enriched1h ago
Tags
botnetsupply chainc2 infrastructuredeveloper targeting
Trending Score37
Source articles1
Independent1
Info Completeness3/14
Missing: cve_id, vendor, product, versions, cvss, epss, cwe, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
May 26, 2026
Discovered by ZDM
May 26, 2026
Actively Exploited
May 26, 2026
Exploit Available
May 26, 2026