GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

Image for article GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
News Source : Internet

News Summary

  • CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm.
  • The persistent software chain campaign targeting software developers through malicious packages and extensions.
  • The end goal of the attacks is to deliver a data-theft framework with credential harvesting, cryptocurrency wallet exfiltration, and system profiling capabilities.
  • As long as developer environments, build pipelines, and code repositories remain under-protected, every organization that consumes software inherits the risk of everyone who produces it.

Must read Articles