GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

An ongoing attack that uses the stolen GitHub tokens to insert malware into hundreds of Python repositories is being fueled by the GlassWorm malware campaign.

By adding obfuscated code to files like setup.py, main.py, and app.py, the attack targets Python projects, including Django apps, ML research code, Streamlit dashboards, and PyPI packages, according to StepSecurity. The malware will be activated by anyone who clones and runs the code or runs pip install from a hacked repository.

The software supply chain security firm claims that the first injections occurred on March 8, 2026. After gaining access to the developer accounts, the attackers use malicious code to rebase the most recent legitimate commits on the default branch of the targeted repositories. They then force-push the changes while preserving the original commit’s message, author, and date.

ForceMemo is the code name for this new GlassWorm campaign offshoot. The next four steps are how the attack is carried out read more about GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *