HomeSecurityGlassWorm attack: Stolen GitHub tokens used to insert malware into Python repos

GlassWorm attack: Stolen GitHub tokens for injecting malware into Python repos

The GlassWorm is being used to support an ongoing attack that leverages stolen GitHub tokens to insert malware into hundreds of Python repositories.

GlassWorm GitHub tokens

“ The attack targets Python projects applications Django, ML research code, Streamlit dashboards, and PyPI packages and app.py. Anyone who runs pip install from a compromised repository or clones and executes the code will activate the malware — including — by adding obfuscated code to files such as setup.py, main.py , ,” StepSecurity said .

See also: Abuse of Microsoft Teams and Quick Assist to distribute A0Backdoor

According to the security firm, the first injections were detected on March 8, 2026. Attackers gain access to developer accounts, reorder the latest legitimate commits in the default branch of the targeted repositories with malicious code , and then force the push of the changes while keeping the original commit message, author, and author date intact.

GlassWorm: New four-step attack

This new variant of the GlassWorm campaign has been codenamed ForceMemo. The attack unfolds through the following four steps:

1. Hacking developers' systems with GlassWorm malware via malicious VS Code and Cursor extensions. The malware contains a special component for stealing secrets, such as GitHub tokens.

2. Using the stolen credentials to force push malicious changes to every repository managed by the compromised GitHub account , rearranging the disguised malware into Python files named “setup.py”, “main.py” or “app.py”.

3. The Base64-encoded payload, added to the end of the Python file, has GlassWorm-like checks to determine if the system is set to Russian. If so, it skips execution. In all other cases, the malware queries the transaction memo field associated with a Solana (which was previously connected to GlassWorm to extract the payload URL).

4. Downloading additional payloads from the server, including encrypted JavaScript designed to steal cryptocurrency and data.

See also: ClickFix attacks spread MacSync infostealer

GlassWorm attack: Stolen GitHub tokens for injecting malware into Python repos

“The first transaction at the C2 address dates back to November 27, 2025 — over three months before the first GitHub repo injections on March 8, 2026. The address has a total of 50 transactions, with the attacker regularly updating the payload URL, sometimes multiple times a day,” says StepSecurity.

The revelation comes as Socket has identified a new variant of GlassWorm that maintains the same core technique while improving persistence and evasion by using extensionPack and extensionDependencies to deliver the malicious payload.

Meanwhile, Aikido Security has linked the GlassWorm creator to a massive campaign that compromised more than 151 GitHub repositories with malicious code hidden within invisible Unicode characters. The decoded payload is configured to retrieve C2 instructions from the same Solana wallet, indicating that the threat actor has targeted GitHub repositories in different attacks.

See also: DRILLAPP Backdoor targets Ukraine with Microsoft Edge debugging

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

GlassWorm attack: Stolen GitHub tokens for injecting malware into Python repos

The use of different delivery methods and obfuscation methods, but the same Solana infrastructure, suggests that ForceMemo is a new delivery vehicle maintained and operated by the GlassWorm threat actor, which has expanded from compromising VS Code extensions to a broader campaign to take over GitHub accounts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS