{"id":242662,"date":"2026-05-27T16:59:19","date_gmt":"2026-05-27T16:59:19","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/27\/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks-techcrunch\/"},"modified":"2026-05-27T16:59:19","modified_gmt":"2026-05-27T16:59:19","slug":"crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/27\/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks-techcrunch\/","title":{"rendered":"CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open-source software developers.<\/p>\n<p class=\"wp-block-paragraph\">The <a rel=\"nofollow noopener\" href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/inside-crowdstrike-takedown-of-a-developer-targeting-botnet\/\" target=\"_blank\">takedown operation<\/a> had the goal of disrupting the activities of the cybercriminals behind the so-called Glassworm botnet, who have been targeting the broader open source software supply chain for two years, according to CrowdStrike.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In recent months, several hacking groups have targeted developers and open source projects to push malicious software to companies and organizations who in turn use that software. These attacks can be effective because they exploit the trust that companies put into code that\u2019s hosted on platforms like GitHub, and the workers behind that code.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAdversaries are no longer just targeting products, they\u2019re targeting the developers who build them,\u201d CrowdStrike wrote in its report about the takedown operation. \u201cDevelopers represent uniquely high-value targets: compromising a single developer\u2019s workstation can cascade into a supply-chain compromise that impacts thousands of downstream organizations and users.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The Glassworm hackers used several strategies to push out their malicious code. This included publishing malicious extensions on a marketplace used by developers; by malvertising \u2014 where hackers pay for sponsored search results that trick victims into downloading malware; and using credentials stolen in previous hacks, which allowed the hijacking of developer accounts and the planting of malware in their code.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the end, the hackers were able to poison \u2014 as CrowdStrike put it\u00a0\u2014 more than 300 GitHub code repositories.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about the Glassworm hacking group? Or about other supply chain attacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/05\/27\/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">by email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/05\/27\/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">.<\/a> \t\t<\/div>\n<p class=\"wp-block-paragraph\">CrowdStrike said it was able to takedown four command-and-control channels used by the Glassworm hackers, which cut the hackers\u2019 access to infected computers and stopped them from delivering more malware. <\/p>\n<p class=\"wp-block-paragraph\">The command-and-control servers relied on the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers, according to CrowdStrike.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not clear on what legal or technical authority CrowdStrike and others operated under to takedown the operation. A spokesperson for CrowdStrike did not immediately comment.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Last week, <a href=\"http:\/\/techcrunch.com\/2026\/05\/19\/hackers-have-compromised-dozens-of-popular-open-source-packages-in-an-ongoing-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">hackers compromised several open source projects<\/a> that pushed out malicious updates in a different hacking campaign that was called \u201cMini Shai-Hulud.\u201d An OpenAI developer <a href=\"http:\/\/techcrunch.com\/2026\/05\/19\/hackers-have-compromised-dozens-of-popular-open-source-packages-in-an-ongoing-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener\">was compromised<\/a> by this group of hackers. In another supply chain attack in March, a suspected North Korean hacker <a href=\"https:\/\/techcrunch.com\/2026\/03\/31\/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware\/\" target=\"_blank\" rel=\"noopener\">hijacked the popular open source software development tool Axios<\/a>, which is used by millions of developers.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/05\/27\/crowdstrike-and-google-take-down-botnet-used-by-hackers-to-target-software-developers-in-supply-chain-attacks\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open-source software developers. The takedown operation had the goal of disrupting the activities of the cybercriminals behind the so-called Glassworm botnet, who have been [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":242663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-242662","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/242662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=242662"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/242662\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/242663"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=242662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=242662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=242662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}