Close Menu
    What's Hot

    Aryna Sabalenka: World No 1 hopes for more women’s matches in French Open night session after beating Naomi Osaka | Tennis News

    Transfer rumors, news: Barcelona to turn to Kane if Álvarez deal falls through

    Sony’s new fight stick and gaming monitor launch in August

    Facebook X (Twitter) Instagram
    Trending
    • Aryna Sabalenka: World No 1 hopes for more women’s matches in French Open night session after beating Naomi Osaka | Tennis News
    • Transfer rumors, news: Barcelona to turn to Kane if Álvarez deal falls through
    • Sony’s new fight stick and gaming monitor launch in August
    • Use AI to augment design, not replace it
    • Iran War Live Updates: Israel Appears to Pull Back From Threat to Strike Beirut
    • Russia Launches Deadly Strikes on Ukraine
    • Iran War Live Updates: Israel Appears to Back Off Threat to Strike Beirut
    • How AI-Powered Customer Service Is Destroying Brand Trust
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

    adminBy adminMarch 16, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 16, 2026Malware / Cryptocurrency

    GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

    The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories.

    “The attack targets Python projects — including Django apps, ML research code, Streamlit dashboards, and PyPI packages — by appending obfuscated code to files like setup.py, main.py, and app.py,” StepSecurity said. “Anyone who runs pip install from a compromised repo or clones and executes the code will trigger the malware.”

    According to the software supply chain security company, the earliest injections date back to March 8, 2026. The attackers, upon gaining access to the developer accounts, rebasing the latest legitimate commits on the default branch of the targeted repositories with malicious code, and then force-pushing the changes, while keeping the original commit’s message, author, and author date intact.

    Cybersecurity

    This new offshoot of the GlassWorm campaign has been codenamed ForceMemo. The attack plays out via the following four steps –

    • Compromise developer systems with GlassWorm malware through malicious VS Code and Cursor extensions. The malware contains a dedicated component to steal secrets, such as GitHub tokens.
    • Use the stolen credentials to force-push malicious changes to every repository managed by the breached GitHub account by rebasing obfuscated malware to Python files named “setup.py,” “main.py,” or “app.py.”
    • The Base64-encoded payload, appended to the end of the Python file, features GlassWorm-like checks to determine if the system has its locale set to Russian. If so, it skips execution. In all other cases, the malware queries the transaction memo field associated with a Solana wallet (“BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC”) previously linked to GlassWorm to extract the payload URL.
    • Download additional payloads from the server, including encrypted JavaScript that’s designed to steal cryptocurrency and data.

    “The earliest transaction on the C2 address dates to November 27, 2025 — over three months before the first GitHub repo injections on March 8, 2026,” StepSecurity said. “The address has 50 transactions total, with the attacker regularly updating the payload URL, sometimes multiple times per day.”

    The disclosure comes as Socket flagged a new iteration of the GlassWorm that technically retains the same core tradecraft while improving survivability and evasion by leveraging extensionPack and extensionDependencies to deliver the malicious payload by means of a transitive distribution model.

    Cybersecurity

    In tandem, Aikido Security also attributed the GlassWorm author to a mass campaign that compromised more than 151 GitHub repositories with malicious code concealed using invisible Unicode characters. Interestingly, the decoded payload is configured to fetch the C2 instructions from the same Solana wallet, indicating that the threat actor has been targeting GitHub repositories in multiple waves.

    The use of different delivery methods and code obfuscation methods, but the same Solana infrastructure, suggests ForceMemo is a new delivery vector maintained and operated by the GlassWorm threat actor, who has now expanded from compromising VS Code extensions to a broader GitHub account takeover.

    “The attacker injects malware by force-pushing to the default branch of compromised repositories,” StepSecurity noted. “This technique rewrites git history, preserves the original commit message and author, and leaves no pull request or commit trail in GitHub’s UI. No other documented supply chain campaign uses this injection method.”

    attack ForcePush GitHub GlassWorm Malware Python Repos stolen Tokens
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy the silence on Iran’s brutality, asks economist Iraj Abedian of SA
    Next Article Sony’s enhanced PSSR upscaling arrives on PS5 Pro today
    admin
    • Website

    Related Posts

    Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    June 2, 2026

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    June 1, 2026

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security

    June 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Aryna Sabalenka: World No 1 hopes for more women’s matches in French Open night session after beating Naomi Osaka | Tennis News

    Transfer rumors, news: Barcelona to turn to Kane if Álvarez deal falls through

    Sony’s new fight stick and gaming monitor launch in August

    Use AI to augment design, not replace it

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by