Find notable cyber news and cases, enriched with sources, timelines, and signals.

GlassWorm multi-stage data-theft malware evolution

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The GlassWorm malware family has evolved into a multi-stage payload chain that steals browser data and crypto-wallet information, increasing risk for Windows and macOS users. It spreads through rogue packages on npm, PyPI, GitHub, and Open VSX, and its operators also abuse maintainer accounts to push poisoned updates. The payload chain includes a RAT, a malicious Chrome extension, and hardware-wallet phishing, enabling session theft, remote access, and credential capture.

Related Happenings

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

Lucide proxy npm packages browser DDoS botnet

Malware Activity
H score31 First: 14.07.2026 10:08 Last: 14.07.2026 10:08 Sources 1

About this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...

Malicious npm packages delivering Windows RAT

Malware Activity
H score3 First: 23.06.2026 11:54 Last: 23.06.2026 11:54 Sources 1

About this happening: A set of malicious npm packages is delivering a Windows-based RAT through a multi-stage install chain, creating risk of credential theft, host profiling, and *...

Sapphire Sleet Mastra npm supply-chain campaign

Campaign
H score42 First: 20.06.2026 17:09 Last: 20.06.2026 17:09 Sources 1

About this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...

SilabRAT session-hijacking crypto-draining malware activity

Malware Activity
H score24 First: 10.06.2026 18:30 Last: 10.06.2026 18:30 Sources 1

About this happening: The SilabRAT MaaS operation is now offering a session-hijacking remote access trojan that can drain cryptocurrency and bypass password and MFA checks, expandin...

Timeline

  1. 25.03.2026 16:26 2 articles · 3mo ago

    GlassWorm evolves into a multi-stage data-theft framework

    Technical Analysis Update

    GlassWorm has evolved into a multi-stage malware campaign that seeds rogue packages across npm, PyPI, GitHub, and the Open VSX marketplace, abuses compromised maintainer accounts to push poisoned updates, and uses Solana-based dead drops and a public Google Calendar event URL to fetch C2 infrastructure and OS-specific payloads. The chain delivers a data-theft framework, a hardware-wallet phishing component that targets Ledger and Trezor devices, and a WebSocket-based JavaScript RAT that steals browser data, bypasses Chrome's app-bound encryption (ABE), and force-installs a Google Chrome extension named Google Docs Offline to capture cookies, localStorage, screenshots, keystrokes, clipboard content, bookmarks, browser history, and targeted session data such as Bybit (.bybit.com) secure-token and deviceid cookies. AFINE also published glassworm-hunter to scan local systems for associated payloads without making network requests during scanning.

    Show sources