URL has been copied successfully!
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories.”The attack targets Python projects, including Django apps, ML research code, Streamlit dashboards, and PyPI packages, by appending obfuscated code to files like setup.py, main.py, and app.py,” StepSecurity said. “Anyone who runs

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/03/glassworm-attack-uses-stolen-github.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link