Signal
GlassWorm campaign evolves with fake browser extension for surveillance
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-03-26 13:00 UTCUpdated 2026-03-26 14:53 UTC
rss
malwarethreat_actorssecurity_toolingincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
The GlassWorm attack campaign has been updated to include a multi-stage framework that targets developers by distributing malicious packages through popular code repositories.
Score total
0.85
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- Recent updates reveal new tactics in the GlassWorm campaign, increasing its stealth and impact.
- The use of blockchain to fetch payloads shows evolving attacker sophistication.
- Widespread developer reliance on open-source packages heightens exposure to this threat.
Why it matters
- Targets developers, risking supply chain security through compromised packages.
- Uses a multi-stage attack including remote access trojans and fake browser extensions for surveillance.
- Compromises credentials and tools, enabling broader attacks on companies and users.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- GlassWorm installs a fake Google Docs Offline Chrome extension to monitor activity and steal data
- GlassWorm targets developers by distributing malicious packages through popular code repositories like npm, GitHub, and PyPI
How sources frame it
- Malwarebytes Threat Analysis: neutral
All evidence
All evidence
Updated GlassWorm attack campaign uncovered
SC Media · scworld.com · 2026-03-26 14:53 UTC
GlassWorm attack installs fake browser extension for surveillance
Malwarebytes Threat Analysis · malwarebytes.com · 2026-03-26 13:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- SC Media (1)
- Malwarebytes Threat Analysis (1)
Top origin domains (this list)
- scworld.com (1)
- malwarebytes.com (1)