<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #GlassWorm</title><description>Cybersecurity articles tagged #GlassWorm on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Glassworm Botnet Infrastructure Disrupted: Solana and DHT C2 Analysis</title><link>https://runtimerebel.com/blog/glassworm-botnet-infrastructure-disrupted-solana-and-dht-c2-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-botnet-infrastructure-disrupted-solana-and-dht-c2-analysis</guid><description>Researchers disrupt the Glassworm botnet, which utilized Solana blockchain and BitTorrent DHT for resilient C2 to target software developers.</description><pubDate>Wed, 27 May 2026 17:12:49 GMT</pubDate><category>GlassWorm</category><category>Solana Blockchain</category><category>Bittorrent Dht</category><category>Supply Chain Attack</category><category>Npm Malware</category></item><item><title>GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2</title><link>https://runtimerebel.com/blog/glassworm-malware-takedown-disruption-of-developer-supply-chain-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-takedown-disruption-of-developer-supply-chain-c2</guid><description>CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.</description><pubDate>Wed, 27 May 2026 13:20:01 GMT</pubDate><category>GlassWorm</category><category>CrowdStrike</category><category>C2 Disruption</category><category>Supply Chain Attack</category><category>Malicious Packages</category></item><item><title>GlassWorm Campaign Leverages Malicious VS Code Extensions</title><link>https://runtimerebel.com/blog/glassworm-campaign-leverages-malicious-vs-code-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-campaign-leverages-malicious-vs-code-extensions</guid><description>Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.</description><pubDate>Tue, 28 Apr 2026 16:45:38 GMT</pubDate><category>GlassWorm</category><category>VS Code</category><category>Open VSX</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Tools</category><category>Application Security</category></item><item><title>GlassWorm Malware: Cloned Open VSX Extensions Target Developers</title><link>https://runtimerebel.com/blog/glassworm-malware-cloned-open-vsx-extensions-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-cloned-open-vsx-extensions-target-developers</guid><description>Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.</description><pubDate>Tue, 28 Apr 2026 12:45:16 GMT</pubDate><category>Open VSX</category><category>GlassWorm</category><category>VS Code</category><category>Checkmarx</category><category>Malware</category><category>Supply Chain Attack</category></item><item><title>GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions</title><link>https://runtimerebel.com/blog/glassworm-malware-resurfaces-via-73-openvsx-sleeper-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-resurfaces-via-73-openvsx-sleeper-extensions</guid><description>A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 &apos;sleeper&apos; extensions, posing a significant supply chain threat to developers.</description><pubDate>Tue, 28 Apr 2026 00:50:03 GMT</pubDate><category>GlassWorm</category><category>Open VSX</category><category>Supply Chain Attack</category><category>Visual Studio Code</category><category>Sleeper Extensions</category><category>Malware</category></item><item><title>GlassWorm Campaign: Zig Dropper Infects Developer IDEs via Open VSX</title><link>https://runtimerebel.com/blog/glassworm-campaign-zig-dropper-infects-developer-ides-via-open-vsx</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-campaign-zig-dropper-infects-developer-ides-via-open-vsx</guid><description>The GlassWorm campaign exploits the Open VSX registry with a malicious Zig-based dropper, impersonating WakaTime to compromise multiple developer IDEs.</description><pubDate>Fri, 10 Apr 2026 16:23:40 GMT</pubDate><category>GlassWorm</category><category>Zig Dropper</category><category>Open VSX</category><category>IDE Security</category><category>WakaTime Spoofing</category></item><item><title>GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery</title><link>https://runtimerebel.com/blog/glassworm-malware-uses-solana-dead-drops-for-stealthy-c2-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-uses-solana-dead-drops-for-stealthy-c2-delivery</guid><description>GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.</description><pubDate>Wed, 25 Mar 2026 16:31:31 GMT</pubDate><category>GlassWorm</category><category>Solana</category><category>RAT</category><category>Information Stealer</category><category>Blockchain Dead Drops</category></item><item><title>GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified</title><link>https://runtimerebel.com/blog/glassworm-supply-chain-attack-400-malicious-repos-identified</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-supply-chain-attack-400-malicious-repos-identified</guid><description>The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.</description><pubDate>Wed, 18 Mar 2026 00:36:52 GMT</pubDate><category>GlassWorm</category><category>NPM Security</category><category>Vscode Extensions</category><category>Supply Chain Attack</category><category>Malware Analysis</category></item><item><title>GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions</title><link>https://runtimerebel.com/blog/glassworm-malware-detecting-obfuscated-payloads-in-browser-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-detecting-obfuscated-payloads-in-browser-extensions</guid><description>Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.</description><pubDate>Tue, 17 Mar 2026 00:33:59 GMT</pubDate><category>GlassWorm</category><category>ChromeLoader</category><category>Browser Security</category><category>Javascript Obfuscation</category><category>Infostealer</category></item><item><title>GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection</title><link>https://runtimerebel.com/blog/glassworm-stolen-github-tokens-fuel-python-malware-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-stolen-github-tokens-fuel-python-malware-injection</guid><description>The GlassWorm campaign uses stolen GitHub tokens to inject malicious code into Python repositories, including Django and machine learning projects.</description><pubDate>Mon, 16 Mar 2026 20:15:27 GMT</pubDate><category>GlassWorm</category><category>GitHub Security</category><category>Python Malware</category><category>Supply Chain Security</category><category>Django</category><category>PyPI</category></item><item><title>ForceMemo: Credential Theft Compromises Python Repositories</title><link>https://runtimerebel.com/blog/forcememo-credential-theft-compromises-python-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/forcememo-credential-theft-compromises-python-repositories</guid><description>Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.</description><pubDate>Mon, 16 Mar 2026 12:24:53 GMT</pubDate><category>ForceMemo</category><category>GlassWorm</category><category>GitHub</category><category>Python</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>GlassWorm Abuses Open VSX Registry in Supply-Chain Attack</title><link>https://runtimerebel.com/blog/glassworm-abuses-open-vsx-registry-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-abuses-open-vsx-registry-in-supply-chain-attack</guid><description>The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.</description><pubDate>Sat, 14 Mar 2026 16:10:23 GMT</pubDate><category>GlassWorm</category><category>Open VSX</category><category>Supply Chain Attack</category><category>VS Code</category><category>Malware</category></item></channel></rss>