GlassWorm
MITRE ATT&CK: S9010 View on attack.mitre.org
Aliases: GlassWorm
- Malware type
- worm
- Family
- Malware family
- Operating systems
- macos, windows
- Related IoCs
- 15 (6 malicious)
- Last IoC activity
- 2026-09-01 22:59:09
- Profile updated
- 2026-07-07 14:33:07
Targeted industries: technology-and-telecommunications financial-services energy-and-utilities
Context
GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems. GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult. GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain. GlassWorm was first reported in October 2025.
Recent IoC activity
6 malicious indicators in Maltiverse are attributed to GlassWorm (S9010). The 6 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | f_ex86.node | 2026-09-01 | 1 |
| file sample | f_ex86.node | 2026-08-26 | 1 |
| file sample | w.node | 2026-08-16 | 1 |
| file sample | 00d7f42ce14bc4c20a5d8d79433a36b2a5ba251af63e7fab41cd23d8cd5fb138 | 2026-08-14 | 1 |
| file sample | c_x64.node | 2026-07-30 | 2 |
| file sample | f_ex86.node | 2026-07-30 | 1 |
Detection coverage
- 339 Sigma rules
Malware & tools used
- Databases (attack-pattern)
- Non-Standard Port (attack-pattern)
- Execution Guardrails (attack-pattern)
- System Time Discovery (attack-pattern)
- Archive via Utility (attack-pattern)
- Web Protocols (attack-pattern)
- Launch Agent (attack-pattern)
- Internal Proxy (attack-pattern)
- Network Device Configuration Dump (attack-pattern)
- Keychain (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Delay Execution (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- Code Repositories (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Data from Local System (attack-pattern)
- Hidden Window (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Financial Theft (attack-pattern)
- Masquerading (attack-pattern)
- Compromise Software Dependencies and Development Tools (attack-pattern)
- Local Data Staging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Invisible Unicode (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Js.Glassworm (report)
- koi.ai — Glassworm First Self Propagating Worm Using Invisible Code Hits Openvsx Marketplace (report)
- MITRE ATT&CK — S9010 (report)
- socket.dev — Glassworm Loader Hits Open Vsx Via Suspected Developer Account Compromise (report)
- aikido.dev — The Return Of The Invisible Threat Hidden Pua Unicode Hits Github Repositorties (report)
- koi.ai — Glassworm Goes Mac Fresh Infrastructure New Tricks (report)
- koi.ai — Glassworm Goes Native Same Infrastructure Hardened Delivery (report)
- koi.ai — Glassworm Returns New Wave Openvsx Malware Expose Attacker Infrastructure (report)
External references
- mitre-attack — S9010
- Koi Glassworm New Tricks December 2025
- Koi Glassworm Extensions November 2025
- Koi Glassworm InvisibleCode October 2025
- Aikido GlassWorm October 2025
- Socket GlassWorm January 2026
- Koi GlassWorm Rust December 2025
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy