CrowdStrike and Google smash major developer botnet – Claril Noticias

Cybersecurity firm CrowdStrike, in collaboration with Google and the Shadowserver Foundation, has successfully dismantled the “Glassworm” botnet, which cybercriminals spent two years using to deploy malware and steal credentials from open-source software developers globally.

Why Hackers Are Targeting Software Developers

The joint takedown operation targeted the Glassworm botnet to disrupt a highly sophisticated threat to the broader open-source software supply chain. In recent months, malicious actors have increasingly focused on developers and open-source projects. By compromising these targets, hackers can inject malicious code into software that is subsequently adopted by major corporations and organisations worldwide.

The Cascading Threat of Supply Chain Attacks

These exploits are particularly dangerous because they abuse the implicit trust companies place in established code repositories, such as GitHub, and the individuals maintaining them. According to CrowdStrike’s official report on the operation, adversaries are shifting their focus from finished products directly to the creators. Compromising a single developer’s workstation can trigger a massive supply-chain breach, impacting thousands of downstream organisations and users.

Inside the Glassworm Attack Methods

The operators behind the Glassworm botnet deployed a multi-pronged strategy to compromise systems and distribute their malicious payloads. This involved publishing infected extensions on popular developer marketplaces, utilising malvertising—where poisoned search engine ads trick users into downloading malware—and leveraging credentials stolen in prior breaches to hijack legitimate developer accounts and inject malware directly into active codebases.

Through these aggressive tactics, the hackers managed to compromise and poison more than 300 GitHub code repositories, posing a severe threat to the open-source community.

How the Takedown Was Executed

To neutralise the threat, CrowdStrike and its partners disabled four critical command-and-control (C2) channels. This swift action effectively severed the cybercriminals’ access to already infected computers, preventing them from deploying further malware or exfiltrating sensitive data.

A Highly Distributed Infrastructure

The technical analysis revealed that the Glassworm hackers relied on a highly diverse and resilient infrastructure to run their operations. Their command-and-control servers utilised the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and various virtual private servers (VPS).

The exact legal and technical mechanisms used to execute this digital takedown remain undisclosed. When approached for comment, CrowdStrike spokesperson Kirsten Speas declined to provide details beyond the information published in the company’s official blog post.

Rising Threat to Open-Source Ecosystems

This operation comes amidst a surge in supply-chain campaigns. Just last week, a separate hacking wave dubbed “Mini Shai-Hulud” compromised several open-source projects, delivering malicious updates that affected at least two OpenAI developers. Furthermore, in March, a suspected North Korean hacking group hijacked Axios, a widely used open-source development tool relied upon by millions of developers worldwide.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *