GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
ID: 2379d18a-bc62-5203-824e-8edc534ebd09
STIX ID: report--2379d18a-bc62-5203-824e-8edc534ebd09
Feed Name: The Hacker News
StepSecurity and other researchers attribute a new offshoot of the GlassWorm campaign — codenamed ForceMemo — to a threat actor that infects developer systems via malicious VS Code and Cursor extensions, steals GitHub tokens, and rebases/force-pushes obfuscated Base64 payloads into Python files (e.g., setup.py, main.py, app.py) across hundreds of repositories; the payloads use a Solana transaction memo linked to a known wallet to retrieve C2 URLs and download additional malware designed to steal cryptocurrency and data, while avoiding execution in Russian locales and hiding activity by preserving original commit metadata.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
