logo

GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

ID: 2379d18a-bc62-5203-824e-8edc534ebd09

STIX ID: report--2379d18a-bc62-5203-824e-8edc534ebd09

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2026-03-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

StepSecurity and other researchers attribute a new offshoot of the GlassWorm campaign — codenamed ForceMemo — to a threat actor that infects developer systems via malicious VS Code and Cursor extensions, steals GitHub tokens, and rebases/force-pushes obfuscated Base64 payloads into Python files (e.g., setup.py, main.py, app.py) across hundreds of repositories; the payloads use a Solana transaction memo linked to a known wallet to retrieve C2 URLs and download additional malware designed to steal cryptocurrency and data, while avoiding execution in Russian locales and hiding activity by preserving original commit metadata.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.