[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjpbkUrHjTeDMKLxdzadRfpE39vqrRcaTfytgvEykBls":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"08bfad03-90d8-46dd-912d-79181bc0560c","glassworm-malware-exploits-package-repositories-and-blockchain-for-covert-operations","8b1cbf91-f497-450f-a5fd-6234f3408756","GlassWorm Malware Exploits Package Repositories and Blockchain for Covert Operations","The GlassWorm campaign demonstrates how attackers exploit trusted software supply chains by compromising popular package repositories (npm, PyPI, GitHub) to distribute malware disguised as legitimate development tools. The malware's use of Solana blockchain transactions as dead drop resolvers shows sophisticated evasion techniques that bypass traditional network monitoring. Users unknowingly install malicious packages or browser extensions, leading to cryptocurrency theft and comprehensive data exfiltration. This attack highlights the critical need for supply chain security verification and user awareness of social engineering tactics targeting developers and crypto users.","**Immediate actions:**\n- Organizations should implement mandatory code signing verification and dependency scanning for all third-party packages before deployment\n- Implement browser security policies that restrict extension installations to approved corporate stores only\n\n**Long-term improvements:**\n- Establish air-gapped development environments with whitelisted package repositories and require manual approval for new dependencies\n- Conduct regular security awareness training focused on supply chain risks, emphasizing verification of package authenticity and recognition of phishing attempts targeting hardware wallet users\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) solutions that can identify suspicious browser extensions and monitor blockchain-related network traffic",[12,13,14,15,16,17],"CIS Control 2","CIS Control 7","NIST SP 800-161","NIST SC-7","NIST AT-2","OWASP SCVS","published","2026-03-25T18:08:59.314765+00:00","2026-03-25T18:08:59.194+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fglassworm-malware-uses-solana-dead.html","glassworm-malware-uses-solana-dead-drops-to-deliver-rat-and-steal-browser-crypto","GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]