Malware

GlassWorm

According to Koi Security, this malware harvests NPM, GitHub, and Git credentials for supply chain propagation. It targets 49 different cryptocurrency wallet extensions to drain funds. It uses stolen credentials to compromise additional packages and extensions, spreading the worm further. Furthermore, it deploys SOCKS proxy servers, turning developer machines into criminal infrastructure and installs hidden VNC servers for complete remote access.

Indicators of Compromise 18

MITRE ATT&CK TTPs 23

Source Articles

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
PEEP is a post-compromise Chromium-based toolkit that installs a malicious browser extension to establish persistence and enable command-and-control (C2) operations within compromised Chrome or Edge browsers. The malware bypasses browser security checks by manipulating Secure Preferences and uses native messaging to execute host-level commands, steal credentials, and exfiltrate browsing data. It communicates with C2 servers every 30 seconds over HTTP, supports remote updates, and includes PowerShell and Python scripts for cross-platform deployment, indicating active targeting of both Windows and Linux environments.
hacker-news ·4d ago
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
OkoBot is a malware framework targeting Windows users, active since April 2025, that injects phishing pages into legitimate cryptocurrency wallet applications like Ledger Live and Trezor Suite to steal recovery phrases. One of its modules, SeedHunter, hooks into Electron-based apps and waits for hardware wallet connections before displaying a malicious recovery page. The framework uses trojanized software and phishing lures to gain access, establishes persistent remote access via SSH and RDP, and deploys multiple surveillance and data-stealing plugins. Kaspersky attributes the campaign to an unknown actor but notes Russian-language artifacts and targeting patterns.
hacker-news ·1mo ago