Cybersecurity & Privacy — 2026-03-17

GlassWorm Supply Chain Attack Expands: 150 GitHub Repos Compromised via Stolen Tokens, 72 Malicious VS Code Extensions

The GlassWorm campaign compromised approximately 150 GitHub repositories between March 3-9 using stolen developer tokens to force-push malware into Python projects including Django apps, ML research code, and PyPI packages. The 'ForceMemo' technique rewrites git history while preserving commit metadata, leaving no visible trail in GitHub's UI. GlassWorm also deployed 72 malicious Open VSX extensions since January. Anyone running pip install from compromised repos triggers the malware. The attack expanded from its October 2025 origin targeting VS Code extensions.

Analysis
The March 16 digests covered the initial GitHub token theft campaign. The expansion to 72 malicious Open VSX extensions broadens the attack surface beyond Python repos to VS Code users. The ForceMemo technique of rewriting git history without traces is novel in supply chain attacks.

View in full brief →

UNCLASSIFIED // OPEN SOURCE