
The GlassWorm malware is being exploited in an active attack that uses compromised GitHub tokens to inject malicious code into hundreds of Python software collections.
“The attack is aimed at Python projects â including Django applications, machine learning research code, Streamlit dashboards, and PyPI programs â by adding concealed code to files like setup.py, main.py, and app.py,” StepSecurity reported. “Running ‘pip install’ from a compromised source or cloning and running the altered code will trigger the malware.”
The software security firm noted that the earliest code injections occurred around March 8, 2026. After gaining access to developer accounts, the attackers rebased legitimate commits onto the default repository branch along with added malicious code, and then used force-push to apply the changes, keeping the original commit data (message, author, date) the same.
This new iteration of the GlassWorm attack is called ForceMemo, and it unfolds in these four stages:
“The first transaction logged on the command-and-control (C2) address dates back to November 27, 2025 â over three months before the first GitHub repository code injections on March 8, 2026,” StepSecurity stated. “This address has had 50 transactions total, with the attacker consistently updating the payload’s URL, often multiple times per day.”
This revelation comes after Socket detected a new version of GlassWorm that uses the same core methods, but enhances its resilience and ability to avoid detection by using extensionPack and extensionDependencies to deliver the malicious paylod, by use of a transitive distribution model.
Additionally, Aikido Security connected the creator of GlassWorm to a mass attack that compromised over 151 GitHub repositories with malicious code, making it hard to spot it using invalid Unicode characters. When decoded payload it accesses the C2 server through the same Solana wallet. This could suggest that the threat actor has been targeting GitHub repositories in multiple attacks.
While varied code delivery methods and obfuscation styles have been noticed, the consistent use of the same Solana infrastructure points to ForceMemo itself as another delivery method under the control and handling of the GlassWorm threat actor whose targets have now broadened from VS Code extensions to encompassing a wider range of GitHub account compromises.
“The attacker inserts the malware by directly force-pushing to the default branch of compromised repositories,” StepSecurity explained. “The approach manipulates the git history, preserving the original commit message and author, and leaves no evidence or any other activity in GitHub’s UI. No other documented supply chain attack deploys code insertion this way.”
Two React Native npm programs – react-native-international-phone-number and react-native-country-select – which belong to the npm user “astroonauta,” were breached to directly push malware-infected versions to the registry without publishing corresponding changes to their GitHub repositories. These instances have been associated with the ForceMemo malware.
The rogue versions, noticed on March 16, 2026, contained a preinstall script that runs a concealed JavaScript program to execute several actions. It skips Russian victims by checking environment variables, then it accesses a hard-coded Solana wallet (“6YGcuyFRJKZtcaYCCFba9fScNUvPkGXodXE1mJiSzqDJ”) – also related to GlassWorm – to retrieve the address and deliver malware specific to each operating system.
“The fully decrypted malware is executed directly in memory, without saving it to the disk, through eval() on macOS/Linux or a Node.js vm.Script sandbox on other platforms,” StepSecurity mentioned. “A persistence lock is written to ~/init.json with the current timestamp; the malware will not re-execute within a 48-hour window on the same machine.”
In further analysis, OpenSourceMalware reported that over 433 projects along with other software have been compromised across several environments: GitHub’s Python and JavaScript environments, VS Code add-ons, and npm software libraries. Attacks lead to an information-stealing program in JavaScript.
(The story was updated to include further information about the malware campaign.)
#attack #enable #force-pushed #github #glassworm #malware #news #python #repos #stolen #tokens #with — News
© Bulletproof Servers. All rights reserved.