Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GlassWorm Malware Exploits GitHub Tokens for Python Attacks

GlassWorm Malware Exploits GitHub Tokens for Python Attacks

Posted on March 16, 2026 By CWS

The GlassWorm malware campaign has recently intensified with a new attack that utilizes stolen GitHub tokens to inject malicious code into a vast array of Python repositories. This operation, affecting numerous Python projects such as Django apps and PyPI packages, is executed by embedding obfuscated code into crucial files like setup.py and app.py. StepSecurity highlights that this malicious code is activated whenever a user executes a pip install command from a compromised repository.

Details of the Attack

Beginning as early as March 8, 2026, this campaign sees attackers gaining unauthorized access to developer accounts. Once inside, they rebase legitimate commits on the default branch with malware-infused code, force-pushing these changes while maintaining the original commit’s metadata. This sophisticated method ensures the malicious modifications are seamlessly integrated without raising immediate suspicions.

The latest iteration of this malware activity, dubbed ForceMemo, unfolds through a series of calculated steps. Initially, GlassWorm malware compromises developer systems via malicious Visual Studio Code extensions. The malware is engineered to extract sensitive information, including GitHub tokens, which are then used to push harmful changes across all repositories managed by the targeted accounts.

Mechanism and Payload

The attackers append a Base64-encoded payload to Python files, incorporating checks to bypass execution if the system locale is set to Russian. If not, the malware consults the transaction memo field of a Solana wallet, previously linked to GlassWorm, to retrieve the payload URL. This process allows the download of additional payloads, including encrypted JavaScript, designed for cryptocurrency and data theft.

StepSecurity notes that the earliest transaction linked to the command-and-control address occurred on November 27, 2025, predating the first GitHub repository compromises by several months. The address has been active, frequently updating the payload URL, sometimes multiple times within a day.

Broader Implications and Response

This disclosure coincides with reports from Socket, indicating that GlassWorm continues to evolve its strategies, employing extensionPack and extensionDependencies for a transitive distribution model. Meanwhile, Aikido Security associates the malware’s author with a broader campaign compromising over 151 GitHub repositories using concealed obfuscation techniques.

The persistent use of a Solana wallet and diverse delivery methods suggest that ForceMemo is a newly developed vector by the GlassWorm operators. By expanding their attack surface from VS Code extensions to GitHub account takeovers, the threat actors demonstrate a sophisticated understanding of software supply chain vulnerabilities.

StepSecurity emphasizes that this attack method is unique in its approach of rewriting git history while preserving commit messages and authorship, leaving no visible trace within GitHub’s interface. This underscores a significant challenge in detecting and mitigating such supply chain attacks, urging developers and security teams to enhance their protective measures.

The Hacker News Tags:Aikido Security, cryptocurrency theft, Cybersecurity, ForceMemo, GitHub tokens, GlassWorm, Malware, Obfuscation, Python repositories, security breach, Socket, software supply chain, Solana wallet, VS Code

Post navigation

Previous Post: Fake FileZilla Sites Distribute Remote Access Trojan
Next Post: Global Outage Disrupts Microsoft Exchange Online Access

Related Posts

CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack CISA Flags Adobe AEM Flaw with Perfect 10.0 Score — Already Under Active Attack The Hacker News
Rethinking Security for Scattered Spider Rethinking Security for Scattered Spider The Hacker News
Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack The Hacker News
Enterprise Security Gaps: Insights from 25 Million Alerts Enterprise Security Gaps: Insights from 25 Million Alerts The Hacker News
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection The Hacker News
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rockwell Automation Addresses Key Security Flaws
  • Enhancing Security: From Visibility to Validation
  • Kodak Acknowledges Data Breach Amid ShinyHunters Threat
  • DragonForce Ransomware Exploits Microsoft Teams Servers
  • Top Attack Surface Exposures to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rockwell Automation Addresses Key Security Flaws
  • Enhancing Security: From Visibility to Validation
  • Kodak Acknowledges Data Breach Amid ShinyHunters Threat
  • DragonForce Ransomware Exploits Microsoft Teams Servers
  • Top Attack Surface Exposures to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark