Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Tom Brady’s CardVault Arrives in Austin With a Friends and Family Kickoff

    May 27, 2026

    Vivienne Jolie-Pitt Could Pass For Her Mom Angelina Jolie

    May 27, 2026

    Nicolas Cage Says Christopher Nolan Won’t Work With Him

    May 27, 2026
    Facebook X (Twitter) Instagram
    Select Language
    Facebook X (Twitter) Instagram
    NEWS ON CLICK
    Subscribe
    Wednesday, May 27
    • Home
      • United States
      • Canada
      • Spain
      • Mexico
    • Top Countries
      • Canada
      • Mexico
      • Spain
      • United States
    • Politics
    • Business
    • Entertainment
    • Fashion
    • Health
    • Science
    • Sports
    • Travel
    NEWS ON CLICK
    Home»Science & Technology»US Science & Tech»CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
    US Science & Tech

    CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks

    News DeskBy News DeskMay 27, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
    Share
    Facebook Twitter Pinterest Email Copy Link

    CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open-source software developers.

    The takedown operation had the goal of disrupting the activities of the cybercriminals behind the so-called Glassworm botnet, who have been targeting the broader open source software supply chain for two years, according to CrowdStrike. 

    In recent months, several hacking groups have targeted developers and open source projects to push malicious software to companies and organizations who in turn use that software. These attacks can be effective because they exploit the trust that companies put into code that’s hosted on platforms like GitHub, and the workers behind that code.

    “Adversaries are no longer just targeting products, they’re targeting the developers who build them,” CrowdStrike wrote in its report about the takedown operation. “Developers represent uniquely high-value targets: compromising a single developer’s workstation can cascade into a supply-chain compromise that impacts thousands of downstream organizations and users.”

    The Glassworm hackers used several strategies to push out their malicious code. This included publishing malicious extensions on a marketplace used by developers; by malvertising — where hackers pay for sponsored search results that trick victims into downloading malware; and using credentials stolen in previous hacks, which allowed the hijacking of developer accounts and the planting of malware in their code. 

    In the end, the hackers were able to poison — as CrowdStrike put it — more than 300 GitHub code repositories. 

    Contact Us

    Do you have more information about the Glassworm hacking group? Or about other supply chain attacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or by email.

    CrowdStrike said it was able to takedown four command-and-control channels used by the Glassworm hackers, which cut the hackers’ access to infected computers and stopped them from delivering more malware.

    The command-and-control servers relied on the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers, according to CrowdStrike.

    It’s not clear on what legal or technical authority CrowdStrike and others operated under to takedown the operation. A spokesperson for CrowdStrike did not immediately comment. 

    Last week, hackers compromised several open source projects that pushed out malicious updates in a different hacking campaign that was called “Mini Shai-Hulud.” An OpenAI developer was compromised by this group of hackers. In another supply chain attack in March, a suspected North Korean hacker hijacked the popular open source software development tool Axios, which is used by millions of developers.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

    Cybercrime Cybersecurity Hackers open source supply chain attack supply chain security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    News Desk
    • Website

    News Desk is the dedicated editorial force behind News On Click. Comprised of experienced journalists, writers, and editors, our team is united by a shared passion for delivering high-quality, credible news to a global audience.

    Related Posts

    US Science & Tech

    Valve Jacks Up Steam Deck Prices By As Much As $300

    May 27, 2026
    US Science & Tech

    Sony Announces True RGB Bravia TV Lineup

    May 27, 2026
    US Science & Tech

    FAA orders SpaceX to investigate Starship V3 booster failure

    May 27, 2026
    US Science & Tech

    ClickHouse triples anualized revenue to $250M, charting a path toward an IPO

    May 27, 2026
    US Science & Tech

    Spotify’s Latest Feature Makes It Easier To Share Podcast Clips

    May 27, 2026
    US Science & Tech

    CD Projekt Red Announces New Witcher 3 Expansion, Songs Of The Past

    May 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Don't Miss

    Tom Brady’s CardVault Arrives in Austin With a Friends and Family Kickoff

    News DeskMay 27, 20260

    Tom Brady‘s trading card and collectibles business CardVault held an invitation-only Friends and Family preview…

    Vivienne Jolie-Pitt Could Pass For Her Mom Angelina Jolie

    May 27, 2026

    Nicolas Cage Says Christopher Nolan Won’t Work With Him

    May 27, 2026

    Pat McAfee’s Baby Spends 36 Hours In NICU, Following C-Section

    May 27, 2026
    Tech news by Newsonclick.com
    Top Posts

    Andy Cohen Reveals Who Helped Crack ‘Summer House’ Leak

    April 27, 2026

    Consumers lost $2.1 billion to social media scams in 2025, FTC reports

    April 27, 2026

    Told He Impregnated Another Woman (VIDEOS)

    April 27, 2026

    Manchester United v Brentford: Text commentary, updates, goals and stats as Maguire and Amad return in Premier League

    April 27, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Editors Picks

    Tom Brady’s CardVault Arrives in Austin With a Friends and Family Kickoff

    May 27, 2026

    Vivienne Jolie-Pitt Could Pass For Her Mom Angelina Jolie

    May 27, 2026

    Nicolas Cage Says Christopher Nolan Won’t Work With Him

    May 27, 2026

    Pat McAfee’s Baby Spends 36 Hours In NICU, Following C-Section

    May 27, 2026
    About Us

    NewsOnClick.com is your reliable source for timely and accurate news. We are committed to delivering unbiased reporting across politics, sports, entertainment, technology, and more. Our mission is to keep you informed with credible, fact-checked content you can trust.

    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube
    Latest Posts

    Tom Brady’s CardVault Arrives in Austin With a Friends and Family Kickoff

    May 27, 2026

    Vivienne Jolie-Pitt Could Pass For Her Mom Angelina Jolie

    May 27, 2026

    Nicolas Cage Says Christopher Nolan Won’t Work With Him

    May 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    • Advertise
    • Contact Us
    © 2026 Newsonclick.com || Designed & Powered by ❤️ Trustmomentum.com.

    Type above and press Enter to search. Press Esc to cancel.