Page 1 of 1

About recent GlassWorm malware

Posted: Thu Apr 09, 2026 12:42 am
by nguyenkhoi
Hi,

I hope you guys are all having a great day.

I have just come across some news about recent GlassWorm malware attacks, targeting at open source softwares.
While I have little to no knowledge about these malwares/ viruses except for running anti-malware softwares,
it is a bit worrying that I and several members in my team are using both the Stable and Beta versions of CC (downladed from offical homepage).

You can have a look at the linke below if you want to read more about it.
https://www.scientificamerican.com/arti ... urce-code/

I wonder how CC developer team is dealing with these, an do you have recommendations for me to do in the mean time?

Thank you for your always kind support!

Re: About recent GlassWorm malware

Posted: Thu Apr 09, 2026 4:18 pm
by daniel
CloudCompare does not rely on that many third party software packages, and definitely not the most widespread.

More importantly, as stated in the article: "The infections spanned JavaScript, TypeScript and Python repositories". We don't use any of these in the CloudCompare application itself (almost only C++ components). And if you are concerned by the Python part, then you can simply not install the Python plugin (which is optional).

Re: About recent GlassWorm malware

Posted: Fri Apr 10, 2026 8:59 am
by nguyenkhoi
Thank you for your information!
I really appreciate it.