CrowdStrike and Google, in collaboration with the Shadowserver Foundation, successfully dismantled the Glassworm botnet. The operation simultaneously disabled four command-and-control channels that utilized blockchain, peer-to-peer networks, and Google Calendar to resist takedowns.

Active since early 2025, Glassworm targeted software developers to initiate supply chain attacks. The malware infected Windows, macOS, and Linux systems through malicious VS Code extensions and compromised npm and Python packages.

The botnet poisoned more than 300 GitHub repositories to facilitate its spread. Attackers aimed to steal developer credentials to compromise software projects and impact downstream users.