GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

2026-05-27T13:24:14Ze9fe447aecc1e6ae01f14655b4376f14e0fbc721e3249ae7f30add2efac14079
active-exploitationai-abusec2-takedowncms-exploitcredential-stealercryptojackinggithub-actions-compromiseincident-responsemalwaresoftware-supply-chainsupply-chain-attackvulnerabilities

What happened

The feed describes a surge of high-impact activity across software supply chains, active exploitation of multiple web and CMS flaws, and coordinated takedowns of attacker infrastructure. Key developments include CrowdStrike/Google/Shadowserver disrupting GlassWorm C2s; cross-ecosystem supply-chain campaigns (TrapDoor, Laravel‑Lang, Packagist) distributing credential-stealers and Linux malware; the Megalodon campaign injecting malicious GitHub Actions into thousands of repos; and multiple actively exploited vulnerabilities (notably a 10.0 CVSS LiteSpeed cPanel plugin flaw and a 9.4 Ghost CMS SQ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e9fe447aecc1e6ae01f14655b4376f14e0fbc721e3249ae7f30add2efac14079
Enrichment time
2026-05-27T13:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.