GlassWorm multi-stage data-theft malware evolution
Malware Activity
Summary
Hide ▲
Show ▼
The GlassWorm malware family has evolved into a multi-stage payload chain that steals browser data and crypto-wallet information, increasing risk for Windows and macOS users. It spreads through rogue packages on npm, PyPI, GitHub, and Open VSX, and its operators also abuse maintainer accounts to push poisoned updates. The payload chain includes a RAT, a malicious Chrome extension, and hardware-wallet phishing, enabling session theft, remote access, and credential capture.
Related Happenings
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
Lucide proxy npm packages browser DDoS botnet
Malware Activity
H score31
First: 14.07.2026 10:08
Last: 14.07.2026 10:08
Sources 1
About this happening:
A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Lucide proxy npm packages browser DDoS botnet
Malware ActivityAbout this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Malicious npm packages delivering Windows RAT
Malware Activity
H score3
First: 23.06.2026 11:54
Last: 23.06.2026 11:54
Sources 1
About this happening:
A set of malicious npm packages is delivering a Windows-based RAT through a multi-stage install chain, creating risk of credential theft, host profiling, and *...
Malicious npm packages delivering Windows RAT
Malware ActivityAbout this happening: A set of malicious npm packages is delivering a Windows-based RAT through a multi-stage install chain, creating risk of credential theft, host profiling, and *...
Sapphire Sleet Mastra npm supply-chain campaign
Campaign
H score42
First: 20.06.2026 17:09
Last: 20.06.2026 17:09
Sources 1
About this happening:
The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Sapphire Sleet Mastra npm supply-chain campaign
CampaignAbout this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
SilabRAT session-hijacking crypto-draining malware activity
Malware Activity
H score24
First: 10.06.2026 18:30
Last: 10.06.2026 18:30
Sources 1
About this happening:
The SilabRAT MaaS operation is now offering a session-hijacking remote access trojan that can drain cryptocurrency and bypass password and MFA checks, expandin...
SilabRAT session-hijacking crypto-draining malware activity
Malware ActivityAbout this happening: The SilabRAT MaaS operation is now offering a session-hijacking remote access trojan that can drain cryptocurrency and bypass password and MFA checks, expandin...
Timeline
-
25.03.2026 16:26 2 articles · 3mo ago
GlassWorm evolves into a multi-stage data-theft framework
Technical Analysis UpdateGlassWorm has evolved into a multi-stage malware campaign that seeds rogue packages across npm, PyPI, GitHub, and the Open VSX marketplace, abuses compromised maintainer accounts to push poisoned updates, and uses Solana-based dead drops and a public Google Calendar event URL to fetch C2 infrastructure and OS-specific payloads. The chain delivers a data-theft framework, a hardware-wallet phishing component that targets Ledger and Trezor devices, and a WebSocket-based JavaScript RAT that steals browser data, bypasses Chrome's app-bound encryption (ABE), and force-installs a Google Chrome extension named Google Docs Offline to capture cookies, localStorage, screenshots, keystrokes, clipboard content, bookmarks, browser history, and targeted session data such as Bybit (.bybit.com) secure-token and deviceid cookies. AFINE also published glassworm-hunter to scan local systems for associated payloads without making network requests during scanning.
Show sources
- GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data — thehackernews.com — 25.03.2026 16:26
- GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data — thehackernews.com — 25.03.2026 16:26