FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
ForceMemo: How Stolen Credentials Turned Hundreds of GitHub Python Repos Into Blockchain-Powered Malware Distributors
NewsSecurity

ForceMemo: How Stolen Credentials Turned Hundreds of GitHub Python Repos Into Blockchain-Powered Malware Distributors

via Dev.toohmygod4h ago

If you thought the GlassWorm campaign was bad, its sequel is worse. ForceMemo — first reported by StepSecurity on March 18, 2026 — is an active supply-chain attack that has silently backdoored hundreds of Python repositories across GitHub. The malware uses Git's force-push to rewrite history, making injections invisible to anyone who doesn't know exactly where to look, and leverages the Solana blockchain as an uncensorable command-and-control channel. This isn't theoretical. It's happening right now, with new repos being compromised daily. From Credential Theft to Mass Compromise ForceMemo is the direct downstream consequence of GlassWorm , the earlier campaign that spread through malicious VS Code and Cursor extensions. GlassWorm's Stage 3 payload includes a dedicated credential harvesting module that steals GitHub tokens from: git credential fill (system credential manager) VS Code extension storage databases ~/.git-credentials (plaintext credential file) The GITHUB_TOKEN environment

Continue reading on Dev.to

Opens in a new tab

Read Full Article
3 views

Related Articles

I replaced all my chargers with this 205W GaN adapter - now I never travel without it
News

I replaced all my chargers with this 205W GaN adapter - now I never travel without it

ZDNet • 4h ago

Anthropic just introduced the Claude Architect Certification — and it’s not easy.
News

Anthropic just introduced the Claude Architect Certification — and it’s not easy.

Medium Programming • 4h ago

Claude Code Has 58 Tips. They’re Not a Menu. Here’s the Stack.
News

Claude Code Has 58 Tips. They’re Not a Menu. Here’s the Stack.

Medium Programming • 4h ago

The Death of Character in Game Console Interfaces
News

The Death of Character in Game Console Interfaces

Lobsters • 4h ago

After testing this Anker, I wish every wireless charger had a thermoelectric cooler
News

After testing this Anker, I wish every wireless charger had a thermoelectric cooler

ZDNet • 4h ago

Discover More Articles