GlassWorm

MITRE ATT&CK: S9010 View on attack.mitre.org

Aliases: GlassWorm

Malware type
worm
Family
Malware family
Operating systems
macos, windows
Related IoCs
15 (6 malicious)
Last IoC activity
2026-09-01 22:59:09
Profile updated
2026-07-07 14:33:07

Targeted industries: technology-and-telecommunications financial-services energy-and-utilities

Context

GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems. GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult. GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain. GlassWorm was first reported in October 2025.

Recent IoC activity

6 malicious indicators in Maltiverse are attributed to GlassWorm (S9010). The 6 most recently updated:

TypeIndicatorUpdatedSources
file sample f_ex86.node 2026-09-01 1
file sample f_ex86.node 2026-08-26 1
file sample w.node 2026-08-16 1
file sample 00d7f42ce14bc4c20a5d8d79433a36b2a5ba251af63e7fab41cd23d8cd5fb138 2026-08-14 1
file sample c_x64.node 2026-07-30 2
file sample f_ex86.node 2026-07-30 1

Detection coverage

  • 339 Sigma rules

Malware & tools used

  • Databases (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Web Protocols (attack-pattern)
  • Launch Agent (attack-pattern)
  • Internal Proxy (attack-pattern)
  • Network Device Configuration Dump (attack-pattern)
  • Keychain (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Delay Execution (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Code Repositories (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Data from Local System (attack-pattern)
  • Hidden Window (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Financial Theft (attack-pattern)
  • Masquerading (attack-pattern)
  • Compromise Software Dependencies and Development Tools (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Invisible Unicode (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Glassworm (report)
  • koi.ai — Glassworm First Self Propagating Worm Using Invisible Code Hits Openvsx Marketplace (report)
  • MITRE ATT&CK — S9010 (report)
  • socket.dev — Glassworm Loader Hits Open Vsx Via Suspected Developer Account Compromise (report)
  • aikido.dev — The Return Of The Invisible Threat Hidden Pua Unicode Hits Github Repositorties (report)
  • koi.ai — Glassworm Goes Mac Fresh Infrastructure New Tricks (report)
  • koi.ai — Glassworm Goes Native Same Infrastructure Hardened Delivery (report)
  • koi.ai — Glassworm Returns New Wave Openvsx Malware Expose Attacker Infrastructure (report)

External references