GlassWorm malware hides remote access trojan (RAT) via Solana. Steals browser and crypto data.
Mar 25, 2026 // 17:33 - Niko Dunn


Cybersecurity experts have identified a new version of the GlassWorm operation, which now uses a complex structure to steal data and install a remote access trojan (RAT). This RAT installs a deceptive Google Chrome extension, disguised as an offline Google Docs version, to steal information.

“It records keystrokes, extracts cookies and session data, captures screen images, and obeys commands from a command and control (C2) server concealed within a Solana blockchain memo,” reported Ilyas Makari, a researcher at Aikido security, last week.

The name GlassWorm refers to a persistent attack that begins by using malicious packages uploaded to platforms like npm, PyPI, GitHub, and Open VSX. The attackers are also known for hijacking project maintainer accounts to distribute compromised updates.

These attacks are sophisticated enough to avoid infecting systems set to Russian as their locale and utilize Solana transactions to find the C2 server (“45.32.150[.]251”) and retrieve payloads specific to the operating system.

The second-stage payload is a framework for stealing data, focusing on credentials, cryptocurrency wallets, and system information. The collected data is compressed into a ZIP file and sent to an external server (“217.69.3[.]152/wall”). It also includes the capability to download and run the final payload.

After the data is sent, the attack proceeds by downloading two additional components: a .NET executable designed for hardware wallet phishing and a JavaScript RAT that utilizes WebSockets to steal web browser data and execute arbitrary code. The RAT payload is obtained from “45.32.150[.]251” using a publicly available Google Calendar event URL as a way to hide the source.

The .NET program detects when a USB device is connected using the Windows Management Instrumentation (WMI) and displays a fake phishing window as soon as a Ledger or Trezor hardware wallet is connected.

“The fake Ledger interface displays a configuration error and requests a 24-word recovery phrase,” Makari explained. “The fake Trezor interface shows a message indicating a failed firmware validation and prompts for the same 24-word phrase. Both include a ‘RESTORE WALLET’ button.”

The malware not only terminates any genuine Ledger Live processes on the Windows system but also redisplays the phishing window if the user closes it. The attacker’s objective is to obtain the wallet recovery phrase and send it to the IP address “45.150.34[.]158.”

The RAT, on the other hand, uses a Distributed Hash Table (DHT) to locate the C2 server. If the DHT method fails, it reverts to the Solana-based hiding method. The RAT then connects to the server to execute various commands on the compromised system:

  • start_hvnc / stop_hvnc, used to deploy a Hidden Virtual Network Computing (HVNC) module for remote desktop control.
  • start_socks / stop_socks, used to start a WebRTC module and operate it as a SOCKS proxy.
  • reget_log, used to steal data from web browsers like Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, and Mozilla Firefox. This component can bypass Chrome’s app-bound encryption (ABE) protections.
  • get_system_info, used to transmit system information.
  • command, used to execute JavaScript provided by the attacker using eval().

The RAT also silently installs a Google Chrome extension named Google Docs Offline on Windows and macOS machines. This extension then connects to a C2 server and receives commands from the attacker, allowing it to collect cookies, localStorage data, the complete Document Object Model (DOM) tree of the current tab, bookmarks, screenshots, keystrokes, clipboard contents, up to 5,000 browser history entries, and a list of installed extensions.

“The extension also monitors specific sessions. It retrieves rules for monitored sites from /api/get-url-for-watch and comes pre-configured to target Bybit (.bybit.com), looking for the secure-token and deviceid cookies,” Aikido stated. “When detected, it sends an auth-detected webhook to /api/webhook/auth-detected containing the cookie data and page metadata. The C2 server can also provide redirect rules that force active tabs to load attacker-controlled URLs.”

This discovery is accompanied by another change in GlassWorm’s tactics. The attackers are now publishing npm packages that imitate the WaterCrawl Model Context Protocol (MCP) server (“@iflow-mcp/watercrawl-watercrawl-mcp) to distribute malicious programs.

“This marks GlassWorm’s first confirmed entry into the MCP environment,” noted Koi security researcher Lotan Sery. “Given the rapid growth of AI-assisted development and the high level of trust placed in MCP servers, this is unlikely to be an isolated incident.”

Developers are advised to be careful when installing Open VSX extensions, npm packages, and MCP servers. It’s also recommended to verify publisher names and package histories, and to avoid blindly trusting download counts. AFINE, a Polish cybersecurity firm, has released an open-source Python tool called glassworm-hunter to help scan systems for components linked to this campaign.

“Glassworm-hunter does not make any network requests during scanning,” researchers Paweł Woyke and Sławomir Zakrzewski stated. “It doesn’t use telemetry, phone home, or automatic update checks. It only accesses local files. The ‘Glassworm-hunter update’ command is the only one that interacts with the network, fetching the latest IoC database from our GitHub and saving it locally.”

#access  #and  #browser  #crypto  #data  #glassworm  #hides  #malware  #news  #rat  #remote  #solana.  #steals  #trojan  #via   —   News