Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Tesla reportedly might sell its China business ahead of a SpaceX merger

    July 31, 2026

    Steelseries Arctis Nova Pro Omni Review: For Multisystem Gamers

    July 31, 2026

    SJY Zeph Open-Back Headphones Review: Music Through Magnets

    July 31, 2026
    Facebook Twitter Instagram
    • Tech
    • Gadgets
    • Spotlight
    • Gaming
    Facebook Twitter Instagram
    iGadgets TechiGadgets Tech
    Subscribe
    • Home
    • Gadgets
    • Insights
    • Apps

      Tesla reportedly might sell its China business ahead of a SpaceX merger

      July 31, 2026

      Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers

      July 31, 2026

      Nscale buys Anyscale as it seeks to own more of the AI compute stack

      July 31, 2026

      Netflix lands global streaming deal for ‘The Walking Dead’

      July 31, 2026

      Meta says AI is making it easier to build new apps — and more are coming

      July 31, 2026
    • Gear
    • Mobiles
      1. Tech
      2. Gadgets
      3. Insights
      4. View All

      Steelseries Arctis Nova Pro Omni Review: For Multisystem Gamers

      July 31, 2026

      SJY Zeph Open-Back Headphones Review: Music Through Magnets

      July 31, 2026

      6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

      July 31, 2026

      Daisy One Review: Comfy and Tactile Headphones

      July 31, 2026

      March Update May Have Weakened The Haptics For Pixel 6 Users

      April 2, 2022

      Project 'Diamond' Is The Galaxy S23, Not A Rollable Smartphone

      April 2, 2022

      The At A Glance Widget Is More Useful After March Update

      April 2, 2022

      Pre-Order The OnePlus 10 Pro For Just $1 In The US

      April 2, 2022

      Motorola Edge+ Review: It Checks A Lot Of Boxes

      April 2, 2022

      This Smartphone Concept Design Is Different… In A Good Way

      April 2, 2022

      Twitter Just Made Searching Your Direct Messages Better

      April 2, 2022

      That Netflix Price Hike Is Starting To Take Place

      April 2, 2022

      Latest Huawei Mobiles P50 and P50 Pro Feature Kirin Chips

      January 15, 2021

      Samsung Galaxy M62 Benchmarked with Galaxy Note10’s Chipset

      January 15, 2021
      9.1

      Review: T-Mobile Winning 5G Race Around the World

      January 15, 2021
      8.9

      Samsung Galaxy S21 Ultra Review: the New King of Android Phones

      January 15, 2021
    • Computing
    iGadgets TechiGadgets Tech
    Home»Apps»CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks
    Apps

    CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks

    adminBy adminMay 27, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Computer code on a screen.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open-source software developers.

    The takedown operation had the goal of disrupting the activities of the cybercriminals behind the so-called Glassworm botnet, who have been targeting the broader open source software supply chain for two years, according to CrowdStrike. 

    In recent months, several hacking groups have targeted developers and open source projects to push malicious software to companies and organizations who in turn use that software. These attacks can be effective because they exploit the trust that companies put into code that’s hosted on platforms like GitHub, and the workers behind that code.

    “Adversaries are no longer just targeting products, they’re targeting the developers who build them,” CrowdStrike wrote in its report about the takedown operation. “Developers represent uniquely high-value targets: compromising a single developer’s workstation can cascade into a supply-chain compromise that impacts thousands of downstream organizations and users.”

    The Glassworm hackers used several strategies to push out their malicious code. This included publishing malicious extensions on a marketplace used by developers; by malvertising — where hackers pay for sponsored search results that trick victims into downloading malware; and using credentials stolen in previous hacks, which allowed the hijacking of developer accounts and the planting of malware in their code. 

    In the end, the hackers were able to poison — as CrowdStrike put it — more than 300 GitHub code repositories. 

    Contact Us

    Do you have more information about the Glassworm hacking group? Or about other supply chain attacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or by email.

    CrowdStrike said it was able to takedown four command-and-control channels used by the Glassworm hackers, which cut the hackers’ access to infected computers and stopped them from delivering more malware.

    The command-and-control servers relied on the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers, according to CrowdStrike.

    It’s not clear on what legal or technical authority CrowdStrike and others operated under to takedown the operation. A spokesperson for CrowdStrike did not immediately comment. 

    Last week, hackers compromised several open source projects that pushed out malicious updates in a different hacking campaign that was called “Mini Shai-Hulud.” An OpenAI developer was compromised by this group of hackers. In another supply chain attack in March, a suspected North Korean hacker hijacked the popular open source software development tool Axios, which is used by millions of developers.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

    Security,cybercrime,cybersecurity,hackers,open source,supply chain attack,supply chain securitycybercrime,cybersecurity,hackers,open source,supply chain attack,supply chain security#CrowdStrike #Google #botnet #hackers #target #software #developers #supply #chain #attacks1779902513

    Attacks botnet Chain CrowdStrike cybercrime cybersecurity developers Google hackers open source software Supply supply chain attack supply chain security Target
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website
    • Tumblr

    Related Posts

    Tesla reportedly might sell its China business ahead of a SpaceX merger

    July 31, 2026

    Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers

    July 31, 2026

    Nscale buys Anyscale as it seeks to own more of the AI compute stack

    July 31, 2026
    Add A Comment

    Leave A Reply Cancel Reply

    Editors Picks
    8.5

    Apple Planning Big Mac Redesign and Half-Sized Old Mac

    January 5, 2021

    Autonomous Driving Startup Attracts Chinese Investor

    January 5, 2021

    Onboard Cameras Allow Disabled Quadcopters to Fly

    January 5, 2021
    Top Reviews
    9.1

    Review: T-Mobile Winning 5G Race Around the World

    By admin
    8.9

    Samsung Galaxy S21 Ultra Review: the New King of Android Phones

    By admin
    8.9

    Xiaomi Mi 10: New Variant with Snapdragon 870 Review

    By admin
    Advertisement
    Demo
    iGadgets Tech
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Tech
    • Gadgets
    • Mobiles
    • Our Authors
    © 2026 ThemeSphere. Designed by WPfastworld.
    "korean kbj​ "korean bj "koreanbj​

    Type above and press Enter to search. Press Esc to cancel.