GlassWorm is driving active software supply chain compromises by abusing stolen credentials to insert malware into widely used open-source code and package ecosystems. One campaign, dubbed ForceMemo, used GitHub tokens stolen from developer machines via malicious VS Code and Cursor extensions to force-push obfuscated payloads into hundreds of Python repositories, including Django apps, ML projects, Streamlit dashboards, and PyPI-linked codebases. The injected code was appended to files such as setup.py, main.py, and app.py, preserved original commit metadata to reduce suspicion, skipped execution on systems using a Russian locale, and retrieved follow-on payload locations through the memo field of a Solana wallet previously associated with GlassWorm.
A separate but related supply chain intrusion hit npm on March 16, when two React Native packages from the same publisher — react-native-country-select@0.3.91 and react-native-international-phone-number@0.11.8 — were backdoored with identical preinstall malware. Installing either package triggered a multi-stage Windows-focused credential and cryptocurrency stealer capable of persistence and additional payload delivery, exposing developers, CI runners, and build agents to compromise through routine dependency installation. A third report on malicious npm packages posing as a Roblox Solara executor describes a different campaign, Cipher stealer, targeting Discord, browsers, and crypto wallets, and does not appear tied to GlassWorm or the compromised React Native packages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By March 16, 2026, security researchers from StepSecurity, Socket, and Aikido had linked multiple attack waves to GlassWorm, including malicious VS Code and Cursor extensions, force-pushed malware in more than 151 GitHub repositories, and the npm package compromises. The reporting tied these activities together through shared Solana-based infrastructure and similar staged malware delivery techniques.
On March 16, 2026, malicious versions of react-native-country-select@0.3.91 and react-native-international-phone-number@0.11.8 were published from the AstrOOnauta account in a coordinated supply-chain attack. The releases added an obfuscated preinstall hook that fetched staged payloads and ultimately deployed a Windows-focused credential and cryptocurrency stealer.
The earliest known ForceMemo repository compromises date to March 8, 2026, when attackers used stolen GitHub tokens to force-push obfuscated malware into Python files such as setup.py, main.py, and app.py. The campaign affected hundreds of repositories and preserved original commit metadata to reduce suspicion.
Researchers said the Solana wallet infrastructure later used for command-and-control in the GlassWorm campaign first showed activity on November 27, 2025. The wallet's transaction memo field was later used to distribute attacker instructions to malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.