GlassWorm

S9010

Malware.View on attack.mitre.org

About this malware

GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems. GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult. GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain. GlassWorm was first reported in October 2025.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1005
Data from Local System

GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads.

T1008
Fallback Channels

GlassWorm has utilized Google Calendar as backup C2.

T1027.013
Encrypted/Encoded File

GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field.

T1027.018
Invisible Unicode

GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors.

T1036
Masquerading

GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects.

T1059.002
AppleScript

GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain.

T1059.007
JavaScript

GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript.

T1071.001
Web Protocols

GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers.

T1074.001
Local Data Staging

GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`.

T1082
System Information Discovery

GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts.

T1090.001
Internal Proxy

GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors.

T1102.001
Dead Drop Resolver

GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data.

T1105
Ingress Tool Transfer

GlassWorm has downloaded additional payloads from C2.

T1124
System Time Discovery

GlassWorm has the ability to check the system’s time zone on the victim device.

T1140
Deobfuscate/Decode Files or Information

GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads.

View all 36 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References6

  1. Aikido GlassWorm October 2025 Open source
    Ilyas Makari. (2025, October 31). The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties. Retrieved April 10, 2026.
  2. Koi GlassWorm Rust December 2025 Open source
    Lotan Sery. (2025, December 10). GlassWorm Goes Native: Same Infrastructure, Hardened Delivery. Retrieved April 10, 2026.
  3. Koi Glassworm Extensions November 2025 Open source
    Idan Dardikman, Yuval Ronen, Lotan Sery. (2025, November 6). GlassWorm Returns: New Wave Strikes as We Expose Attacker Infrastructure. Retrieved April 10, 2026.
  4. Koi Glassworm InvisibleCode October 2025 Open source
    Idan Dardikman. (2025, October 18). GlassWorm: First Self-Propagating Worm Using Invisible Code Hits OpenVSX Marketplace. Retrieved April 10, 2026.
  5. Koi Glassworm New Tricks December 2025 Open source
    Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.
  6. Socket GlassWorm January 2026 Open source
    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.