Última hora
RUПрезидент Казахстана призвал Путина остановить войну в УкраинеRUДжаред Лето обвинили в сексуальных преступлениях: 10 женщин рассказали о своих историяхARالجيش الإسرائيلي يتهم حزب الله بخرق وقف إطلاق النار في جنوب لبنانINTLLibya Plunged into Darkness: Protests Erupt Over Chronic Power Cuts Amid HeatwaveEUEU Trade Tensions with China Escalate Amid Industry Concerns and Conflict-of-Interest QuestionsARباشينيان: مشكلة الاتحاد الاقتصادي الأوراسي مع أرمينيا تشير إلى شلل الاتحادDEKritik nach Anschlag am CSD: Berliner Justiz verteidigt sich - Täter war polizeibekanntTRIrak Cumhurbaşkanlığı, ABD ve Suudi Arabistan'ın Ortak Saldırılara Tepki GösterdiITSilvia Calandrelli nuova presidente della Fondazione Accademia del Cinema Italiano - Premi David di DonatelloSEKvinnas kropp hittad i resväska i Aten - dödsorsak okändRUПрезидент Казахстана призвал Путина остановить войну в УкраинеRUДжаред Лето обвинили в сексуальных преступлениях: 10 женщин рассказали о своих историяхARالجيش الإسرائيلي يتهم حزب الله بخرق وقف إطلاق النار في جنوب لبنانINTLLibya Plunged into Darkness: Protests Erupt Over Chronic Power Cuts Amid HeatwaveEUEU Trade Tensions with China Escalate Amid Industry Concerns and Conflict-of-Interest QuestionsARباشينيان: مشكلة الاتحاد الاقتصادي الأوراسي مع أرمينيا تشير إلى شلل الاتحادDEKritik nach Anschlag am CSD: Berliner Justiz verteidigt sich - Täter war polizeibekanntTRIrak Cumhurbaşkanlığı, ABD ve Suudi Arabistan'ın Ortak Saldırılara Tepki GösterdiITSilvia Calandrelli nuova presidente della Fondazione Accademia del Cinema Italiano - Premi David di DonatelloSEKvinnas kropp hittad i resväska i Aten - dödsorsak okänd
Newsgather
AtrásCrowdStrike Takes Down Glassworm Botnet Targeting Open Source Software Developers
CrowdStrike Takes Down Glassworm Botnet Targeting Open Source Software Developers
Tecnología
TechCrunch30/5/2026Tecnología2 min de lecturaUnited States

CrowdStrike Takes Down Glassworm Botnet Targeting Open Source Software Developers

En resumen

CrowdStrike, with Google and Shadowserver, dismantled the Glassworm botnet, which targeted open source software developers to spread malware and steal passwords, compromising over 300 GitHub repositories.

Resumen generado por IA

Tamaño de fuente

CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open source software developers. The takedown operation had the goal of disrupting the activities of the cybercriminals behind the so-called Glassworm botnet, who have been targeting the broader open source software supply chain for two years, according to CrowdStrike. In recent months, several hacking groups have targeted developers and open source projects to push malicious software to companies and organizations who in turn use that software. These attacks can be effective because they exploit the trust that companies put into code that’s hosted on platforms like GitHub, and the workers behind that code. “Adversaries are no longer just targeting products, they’re targeting the developers who build them,” CrowdStrike wrote in its report about the takedown operation. “Developers represent uniquely high-value targets: compromising a single developer’s workstation can cascade into a supply-chain compromise that impacts thousands of downstream organizations and users.” The Glassworm hackers used several strategies to push out their malicious code. This included publishing malicious extensions on a marketplace used by developers; malvertising — where hackers pay for sponsored search results that trick victims into downloading malware; and using credentials stolen in previous hacks, which allowed the hijacking of developer accounts and the planting of malware in their code. In the end, the hackers were able to poison — as CrowdStrike put it — more than 300 GitHub code repositories. CrowdStrike said it was able to take down four command-and-control channels used by the Glassworm hackers, which cut the hackers’ access to infected computers and stopped them from delivering more malware. The command-and-control servers relied on the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers, according to CrowdStrike. It’s not clear on what legal or technical authority CrowdStrike and others operated under to take down the operation. When asked by TechCrunch, CrowdStrike spokesperson Kirsten Speas declined to comment beyond the company’s blog. Last week, hackers compromised several open source projects that pushed out malicious updates in a different hacking campaign that was called “Mini Shai-Hulud.” At least two OpenAI developers were compromised by this group of hackers. In another supply chain attack in March, a suspected North Korean hacker hijacked the popular open source software development tool Axios, which is used by millions of developers. Updated the number of compromised OpenAI developers and included comment from CrowdStrike.

Temas relacionados

This article was originally published by TechCrunch.

Noticias relacionadas

OpenAI Working on 'Family of Devices' for AI Interaction, Addresses Trust Concerns
Tecnología·hace 18 horas

OpenAI Working on 'Family of Devices' for AI Interaction, Addresses Trust Concerns

OpenAI President Greg Brockman reveals the company is developing a 'family of devices' for AI interaction, without confirming specifics like a rumored smart speaker or wearable. He emphasizes focus on internal innovation amid Apple lawsuit and discusses future voice-centric computer interaction, as well as efforts to address AI trust issues with verifiable data privacy guarantees.

The Verge
2 min de lectura
Más sobre este temaGlassworm botnet