Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ForceMemo Malware Compromises GitHub Python Repositories

ForceMemo Malware Compromises GitHub Python Repositories

Posted on March 18, 2026 By CWS

ForceMemo Malware Targeting GitHub Repositories

A sophisticated malware campaign, dubbed ForceMemo, is currently targeting GitHub accounts, embedding covert malicious code into Python repositories. This operation, which began impacting repositories on March 8, 2026, remains active and poses a significant threat to developers worldwide.

The ForceMemo campaign primarily targets a wide array of Python projects, including those related to Django applications, machine learning, and various APIs. The attackers inject obfuscated code into key files like setup.py and main.py, which activates when these compromised repositories are cloned or packages installed.

Technical Mechanisms of the Attack

The ForceMemo malware exploits Git’s force-push functionality to overwrite repository history stealthily. This method allows attackers to append malicious code without creating visible changes in the commit history, thus evading detection. The preservation of commit messages and author details adds a layer of deception, with only subtle discrepancies in author and committer dates hinting at tampering.

StepSecurity researchers, who initially flagged the campaign, identified the use of Solana blockchain for command-and-control communications, making the infrastructure resilient to takedowns. The malware employs multiple layers of obfuscation, including base64 decoding and zlib decompression, to conceal its payload.

Connection to GlassWorm Infostealer

Investigations have traced the source of account compromises to GlassWorm, an infostealer that propagates through malicious extensions in VS Code. This infostealer extracts GitHub credentials, enabling attackers to commandeer repositories. Accounts like BierOne and HydroRoll-Team have already suffered significant breaches as a result.

The stolen credentials provide attackers the ability to force-push changes, infecting hundreds of repositories with the same malware. This widespread attack has compromised numerous Python projects, making it a major concern within the developer community.

Protective Measures and Recommendations

To mitigate the risks posed by ForceMemo, developers are encouraged to search for specific markers like lzcdrtfxyqiplpd in cloned files and check for unauthorized directories such as node-v22.9.0 in their systems. Additionally, verifying that the default branch aligns with the last known legitimate commit is crucial.

By closely monitoring GitHub logs for discrepancies in author and committer dates, developers can identify potential breaches. Implementing these preventive measures is essential to maintaining the integrity of Python projects and safeguarding against further attacks.

Stay updated with the latest developments by following us on Google News, LinkedIn, and X. Set CSN as a preferred source for timely updates on cybersecurity threats.

Cyber Security News Tags:Blockchain, Cybersecurity, developer security, Django, ForceMemo, GitHub, GitHub tokens, GlassWorm, machine learning, Malware, obfuscated code, Open Source, Python, supply chain attack, VS Code

Post navigation

Previous Post: Iranian Hackers Exploit Stolen Credentials in Stryker Cyberattack
Next Post: Nine IP KVM Flaws Risk Unauthorized Root Access

Related Posts

New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins Cyber Security News
Microsoft Investigation Teams text-to-speech Functionality Issue Impacting Users Microsoft Investigation Teams text-to-speech Functionality Issue Impacting Users Cyber Security News
PyPI Warns of New Phishing Attack Targeting Developers With Fake PyPI site PyPI Warns of New Phishing Attack Targeting Developers With Fake PyPI site Cyber Security News
Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools Cyber Security News
Android Security Update – Patch for Vulnerabilities that Allows Privilege Escalation Cyber Security News
FIN6 Hackers Mimic as Job Seekers to Target Recruiters with Weaponized Resumes FIN6 Hackers Mimic as Job Seekers to Target Recruiters with Weaponized Resumes Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Native Emerges with $42M to Enhance Cloud Security
  • Emerging Malware Threatens Network Devices with DDoS and Crypto-Mining
  • Join the Supply Chain & Risk Summit for Key Insights
  • Cyber Conflict Intensifies Amid Iran and US-Israeli Tensions
  • AI in SaaS: Uncovering Hidden Risks and Security Challenges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Native Emerges with $42M to Enhance Cloud Security
  • Emerging Malware Threatens Network Devices with DDoS and Crypto-Mining
  • Join the Supply Chain & Risk Summit for Key Insights
  • Cyber Conflict Intensifies Amid Iran and US-Israeli Tensions
  • AI in SaaS: Uncovering Hidden Risks and Security Challenges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark