How Google and CrowdStrike Cracked Down on Glassworm Botnet
What to know about Software Supply Chain Vulnerability
Google, CrowdStrike, and the Shadowserver Foundation collaborated to dismantle the Glassworm botnet, which targeted software developers through compromised IDE extensions and packages. The botnet utilized a resilient, decentralized infrastructure involving the Solana blockchain, BitTorrent, and Google Calendar to maintain command and control.
Coverage spectrum
Coverage gap: Low Left coverage5 sources compared across this story cluster. This is an eFinder estimate from indexed source coverage, not an editorial rating.
What happened
How Google and CrowdStrike Cracked Down on Glassworm Botnet The takedown of the Glassworm botnet could provide some relief for developers in this year plagued with software supply chain attacks.
Why it matters
This week, CrowdStrike dismantled a global botnet designed to withstand traditional takedown efforts, through a combined operation with Google and the Shadowserver Foundation.
Common ground
The firm's Counter Adversary Operations team led the operation targeting the stubborn malware infrastructure that used four separate command and control channels – designed to remain active even if parts of the network were disabled.
Perspective signals
The tension in the story is sharpened by Loaded Language: language that can make the dispute feel more urgent, personal, or adversarial than the underlying facts alone.
Follow-up questions
- What new context would change how readers understand this Software Supply Chain Vulnerability story?
- What evidence would most clearly confirm or weaken the claim that Attackers had also compromised npm and Python packages, introducing malicious code through post-install hooks and set-up scripts?
- How does this story connect Software Supply Chain Vulnerability with Cybersecurity Collaboration over the next few days?
Google, CrowdStrike, and the Shadowserver Foundation collaborated to dismantle the Glassworm botnet, which targeted software developers through compromised IDE extensions and packages. The botnet utilized a resilient, decentralized infrastructure involving the Solana blockchain, BitTorrent, and Google Calendar to maintain command and control.
analyticsAnalysis
psychologyPropaganda Techniques Detected
eFinder identified 1 propaganda technique in this article. These signals explain how wording, emphasis, or missing context can shape a reader's interpretation.
fact_checkClaims Checked
eFinder analyzed this article and checked 13 claims against available evidence, cross-references, web search, and Wikipedia. Here is what the fact-checking layer found.
https://phoenix.security/accelerating-supply-chain-attacks-n…
https://www.kodemsecurity.com/resources/malicious-react-nati…
https://www.stepsecurity.io/blog/malicious-npm-releases-foun…
https://news.google.com/stories/CAAqNggKIjBDQklTSGpvSmMzUnZj…
https://tech.yahoo.com/cybersecurity/articles/crowdstrike-ta…
https://www.opensourceforu.com/2026/05/github-npm-and-python…
https://securityaffairs.com/192749/cyber-crime/how-cybersecu…
https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-ta…
https://x.com/rst_cloud/status/2059771327200838105
https://en.wikipedia.org/wiki/Open_VSX
https://en.wikipedia.org/wiki/Chaoborus
https://en.wikipedia.org/wiki/Chaoborus_edulis
https://supplychaindigital.com/news/how-the-glassworm-takedo…
https://biggo.com/news/202605271821_CrowdStrike-takes-down-G…
https://www.bleepingcomputer.com/news/security/glassworm-bot…
https://www.facebook.com/groups/skillsarewa/posts/2678948560…
https://mlq.ai/news/crowdstrike-and-google-dismantle-glasswo…
https://thehackernews.com/search/label/Visual+Studio+Code?m=…
https://en.wikipedia.org/wiki/Open_VSX
https://malpedia.caad.fkie.fraunhofer.de/details/js.glasswor…
https://malpedia.caad.fkie.fraunhofer.de/library/7b51635e-61…
https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-ta…
https://www.techzine.eu/news/security/141647/crowdstrike-tak…
https://mlq.ai/news/crowdstrike-and-google-dismantle-glasswo…