Threats · 182 days ago
Attackers used GlassWorm‑stolen GitHub tokens to access hundreds of developer accounts and force‑push obfuscated malware into Python repositories. The injected code appends Base64 payloads to files like setup.py, main.py, and app.py and fetches encrypted JavaScript via a Solana memo‑controlled URL to steal cryptocurrency and data. Commits preserve original author and message, reducing obvious traces and increasing supply‑chain risk to Django, ML, PyPI and Streamlit projects.
2 sources covering this story
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
GlassWorm campaign injects malware into GitHub Python repos using stolen tokens since March 8, 2026, exposing developers to supply-chain compromise.
ForceMemo: Python Repositories Compromised in GlassWorm Aftermath
Hundreds of GitHub accounts were accessed using credentials stolen in the VS Code GlassWorm campaign.
Part of the PlainSec briefing for 2026-03-17