Malware
GlassWorm
According to Koi Security, this malware harvests NPM, GitHub, and Git credentials for supply chain propagation. It targets 49 different cryptocurrency wallet extensions to drain funds. It uses stolen credentials to compromise additional packages and extensions, spreading the worm further. Furthermore, it deploys SOCKS proxy servers, turning developer machines into criminal infrastructure and installs hidden VNC servers for complete remote access.
Indicators of Compromise 9
MITRE ATT&CK TTPs 17
T1003 T1013 T1021.001 T1027 T1055 T1059.001 T1068 T1070.004 T1078.001 T1082 T1090 T1105 T1136.001 T1218.011 T1548.002 T1557 T1566
OS Credential Dumping
Credential Access
T1013
Remote Desktop Protocol
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
File Deletion
Defense Evasion
Default Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Local Account
Persistence
Rundll32
Defense Evasion
Bypass User Account Control
Privilege Escalation
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access