Description
GlassWorm is a worm that spreads through network shares and browser and development tool extensions while providing backdoor access to infected systems. It hides malicious logic in ways that evade casual inspection, including invisible code paths, and it can steal credentials, hijack accounts, and deploy additional payloads on compromised machines. Its blend of worm propagation and supply chain style distribution makes it a notable threat to developer and enterprise environments alike.
Stats
- First seen
- January 2026
- Last seen
- October 2026
MITRE ATT&CK techniques
36 techniques across 9 tactics.
TA0001 Initial Access
TA0003 Persistence
TA0005 Stealth
TA0006 Credential Access
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
Alert name variants
| Alert Name |
|---|
| Generic.JS.GlassWorm.B.0545ED0A |
| Generic.JS.GlassWorm.B.055F5855 |
| Generic.JS.GlassWorm.B.07EB88AD |
| Generic.JS.GlassWorm.B.0D1FD0A4 |
| Generic.JS.GlassWorm.B.1ACDA93E |
| Generic.JS.GlassWorm.B.1CC1387F |
| Generic.JS.GlassWorm.B.2254E46F |
| Generic.JS.GlassWorm.B.25398F0D |
| Generic.JS.GlassWorm.B.27DBD89D |
| Generic.JS.GlassWorm.B.302FB7AF |
