Glassworm Threat Actor Returns with Unicode-Based Supply Chain Attacks on GitHub, npm, and VS Code
By
robinhouston
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Summary
The Glassworm threat actor has returned with a new wave of supply chain attacks using invisible Unicode characters to compromise software repositories. The attacks target GitHub repositories, npm packages, and VS Code extensions, affecting over 150 repositories including notable projects from Wasmer, Reworm, and opencode-bench. This technique hides malicious code within invisible Unicode characters that appear as normal whitespace to developers, making detection difficult. The campaign represents a sophisticated software supply chain attack that exploits trust in open-source repositories.
Key quotes
· 4 pulledThe invisible threat we've been tracking for nearly a year is back.
This month, the same actor is back, and among the affected repositories are some notable names: a repo from Wasmer, Reworm, and opencode-bench from anomaly
Researchers uncovered malware hidden in invisible Unicode characters across 150+ GitHub repositories, plus npm packages and VS Code extensions.
hidden Unicode characters were being used to compromise GitHub repositories, tracing the technique back to a threat actor named Glassworm
You might also wanna read
Glassworm Malware Campaign Targets Developers via npm, PyPI, OpenVSX, and GitHub
Glassworm is a dangerous malware campaign targeting software developers by abusing trusted platforms including npm, PyPI, OpenVSX, and GitHu
cybersecuritynews.com·4d agoGlassworm botnet targeting software developers taken down by CrowdStrike, Google, and Shadowserver
A coordinated takedown operation by CrowdStrike, Google, and the Shadowserver Foundation dismantled the Glassworm botnet on 26 May 2024. The
CrowdStrike, Google, and Shadowserver dismantle Glassworm botnet targeting open-source developers
CrowdStrike, in collaboration with Google and Shadowserver, has taken down the Glassworm botnet, which cybercriminals used for two years to
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
CrowdStrike, Google, and Shadowserver dismantle Glassworm botnet targeting open-source developers
CrowdStrike, in collaboration with Google and the nonprofit Shadowserver, has taken down the Glassworm botnet — a cybercriminal operation th
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
