logo

ForceMemo Hijacks GitHub Accounts, Backdoors Python Repos

ID: 62060c67-a2e8-52b6-8543-e1a2672020d6

STIX ID: report--62060c67-a2e8-52b6-8543-e1a2672020d6

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ForceMemo is an active supply‑chain campaign that hijacks developer GitHub accounts (via GlassWorm‑harvested credentials) to force‑push obfuscated Python backdoors into popular Python projects; the injected stub queries a specific Solana wallet for on‑chain C2 instructions and fetches an encrypted Node.js payload that acts as an info‑stealer, with hundreds of repos impacted and clear indicators (marker variable lzcdrtfxyqiplpd) for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.