Find notable cyber news and cases, enriched with sources, timelines, and signals.

GlassWorm open-source supply-chain campaign targeting developers

Campaign
First reported
Last updated
Happening score
H score 46
2 unique sources, 4 articles

Summary

Hide ▲

GlassWorm shifted from hidden Open VSX extension updates into a broader GitHub, npm, and VS Code/OpenVSX supply-chain campaign. Early reporting said seemingly standalone extensions later pulled in a GlassWorm-linked dependency, while Socket found at least 72 additional malicious Open VSX extensions and Open VSX removed them. Later reporting tied the operation to 433 compromised components this month and to 73 cloned VS Code extensions in GlassWorm v2, with six confirmed malicious and the rest used as sleeper packages. The payload chain uses GitHub-hosted VSIX files, a Zig dropper, and Solana-based C2 to steal credentials, wallet data, SSH keys, and other developer data.

Related Happenings

Deadcode09284814 malicious npm packages delivering Phantom Bot and infostealers

Malware Activity
H score22 First: 18.05.2026 11:57 Last: 18.05.2026 11:57 Sources 1

About this happening: Four npm packages published by deadcode09284814 were found delivering information-stealing malware and Phantom Bot DDoS capability, putting installers at risk of *...

Mini Shai-Hulud supply-chain campaign targeting npm and PyPI

Campaign
H score45 First: 12.05.2026 17:45 Last: 12.05.2026 17:45 Sources 1

About this happening: The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...

Latest development: 21.05.2026 11:00

Grafana Labs said its GitHub environment was accessed and its codebase downloaded, with additional internal operational information taken from GitHub repositories, after compromise linked to the Mini Shai-Hulud campaign and TanStack npm packages. Grafana said it first spotted malicious activity on May 11, discovered the unauthorized download on May 17, and after contact from the ransom gang rotated automation tokens, enabled enhanced monitoring, audited commits since the May 11 incident, and hardened its GitHub security posture, while saying there is no indication customer production systems or operations were compromised.

Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials

Campaign
H score56 First: 12.05.2026 14:29 Last: 12.05.2026 14:29 Sources 1

About this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...

Mini Shai-Hulud npm supply-chain malware wave

Malware Activity
H score68 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...

Latest development: 09.06.2026 18:42

On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.

TeamPCP Mini Shai-Hulud npm supply-chain campaign

Campaign
H score75 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread tro...

Timeline

  1. 17.03.2026 23:42 3 articles · 4mo ago

    GlassWorm renews multi-platform campaign across GitHub, npm, and VSCode/OpenVSX

    Campaign Scope Update

    GlassWorm renewed its supply-chain campaign against GitHub, npm, and VSCode/OpenVSX, with researchers identifying 433 compromised components this month across 200 GitHub Python repositories, 151 GitHub JS/TS repositories, 72 VSCode/OpenVSX extensions, and 10 npm packages. The operators compromised GitHub accounts to force-push malicious commits, published obfuscated code using invisible Unicode characters, and used Solana blockchain transactions as C2 to deliver a Node.js runtime and a JavaScript-based information stealer that targets cryptocurrency wallet data, credentials, access tokens, SSH keys, and developer environment data.

    Show sources
  2. 14.03.2026 14:55 1 articles · 4mo ago

    GlassWorm open-source supply-chain campaign targeting developers

    Initial Disclosure

    The earliest visible phase relied on seemingly standalone Open VSX extensions that later updated to pull in a GlassWorm-linked dependency. That transitive change created a hidden delivery path before the malicious payload became apparent.

    Show sources