Glassworm botnet dismantled after campaign against developer tooling
One of the largest supply chain campaigns of the past year, dubbed Glassworm, has been neutralised in a coordinated takedown by CrowdStrike, Google and ShadowServer. The campaign began in early 2025 and targeted developers through compromised Visual Studio Code extensions, language-specific package managers and GitHub source code repositories.
The infrastructure was deliberately resilient, using blockchain, peer-to-peer communication and legitimate web services as command channels. That made the takedown difficult, but the operation also demonstrates that novel command-and-control technology does not make threat actors untouchable.
What this means for your organisation
Developer machines are often the least controlled machines in an organisation, and at the same time the ones with the most access: source code, build environments, cloud keys and production databases. An attack that begins in a code editor extension bypasses both the firewall and the procurement process. For organisations that build their own software, this is a path rarely covered by supplier management.
Berigo recommends
- Define which editor extensions and package sources are permitted, and enforce it in the development environment rather than leaving the choice to each individual.
- Review which secrets are actually reachable from a developer machine, and move them into a secrets store with short-lived credentials.
- Bring endpoint monitoring on developer machines up to server standard, not office laptop standard.
- Include the developer toolchain in your supply chain risk assessment, not just contracted third-party suppliers.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch