Malware.View on attack.mitre.org
GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems. GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult. GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain. GlassWorm was first reported in October 2025.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
GlassWorm has collected local data from a compromised host to include desktop cryptocurrency wallet data, and documents from within Desktop, Documents, and Downloads. |
| T1008 Fallback Channels |
GlassWorm has utilized Google Calendar as backup C2. |
| T1027.013 Encrypted/Encoded File |
GlassWorm has leveraged AES-256-CBC encryption to obfuscate its malicious JavaScript payload. GlassWorm has also utilized Base64 encoding to obfuscate the C2 details stored in the Solana memo field. |
| T1027.018 Invisible Unicode |
GlassWorm has utilized invisible Unicode Private Use Area (PUA) characters to obfuscate its malicious code so that it does not render in code editors. |
| T1036 Masquerading |
GlassWorm has masqueraded as legitimate VSCode extensions. GlassWorm has also impersonated Github projects. |
| T1059.002 AppleScript |
GlassWorm has utilized AppleScript to include `set keychainPassword to do shell script` to execute shell command that retrieves passwords from the macOS keychain. |
| T1059.007 JavaScript |
GlassWorm has leveraged JavaScript to execute its malicious code to include its hidden Unicode characters using the `eval` call. GlassWorm has also utilized encrypted payloads compiled in JavaScript. |
| T1071.001 Web Protocols |
GlassWorm has used HTTP for C2 and extracts data from the HTTP response headers. |
| T1074.001 Local Data Staging |
GlassWorm has staged collected data in a working directory within a temp folder to include `/tmp/ijewf`. |
| T1082 System Information Discovery |
GlassWorm has the ability to check the OS of the victim host. GlassWorm has checked whether the OS platform value includes `darwin` prior to execution of macOS specific scripts. |
| T1090.001 Internal Proxy |
GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors. |
| T1102.001 Dead Drop Resolver |
GlassWorm has leveraged blockchain-based C2 infrastructure to include Solana blockchain that contains additional C2 details within the memo field. GlassWorm has also leveraged Google Calendar to host encoded data. |
| T1105 Ingress Tool Transfer |
GlassWorm has downloaded additional payloads from C2. |
| T1124 System Time Discovery |
GlassWorm has the ability to check the system’s time zone on the victim device. |
| T1140 Deobfuscate/Decode Files or Information |
GlassWorm has decoded its Base64 instructions. GlassWorm has also decrypted its AES protected payloads. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.