Stolen GitHub Tokens Inject Malware into Python Repositories

Attackers used GlassWorm‑stolen GitHub tokens to access hundreds of developer accounts and force‑push obfuscated malware into Python repositories. The injected code appends Base64 payloads to files like setup.py, main.py, and app.py and fetches encrypted JavaScript via a Solana memo‑controlled URL to steal cryptocurrency and data. Commits preserve original author and message, reducing obvious traces and increasing supply‑chain risk to Django, ML, PyPI and Streamlit projects.

Part of the PlainSec briefing for 2026-03-17

Sources