Cybersecurity firms CrowdStrike and Google say they have disrupted the Glassworm botnet, which attackers use to carry out supply-chain intrusions aimed at software developers. Across reporting, the botnet is described as being leveraged to compromise open-source software projects and then reach the developers and organizations that rely on that software. Infosecurity Magazine reports that the operators have been targeting software developers since at least early 2025. TechCrunch adds that the attackers infect open-source projects with malware, using those infections to compromise downstream victims by exploiting the trust and distribution pathways of widely used code. The Register similarly frames the campaign as developer-targeted and consistent with broader trends in supply-chain attacks.

The sources collectively indicate that the disruption effort involves taking down or otherwise dismantling infrastructure associated with the botnet, although they provide limited technical detail in the material provided here. Overall, the reporting focuses on the botnet’s role in enabling malware distribution through software development ecosystems and the resulting risk to developers and companies that adopt the affected software.