# GlassWorm Campaign Weaponizes Stolen GitHub Credentials to Mass-Inject Malware Into Python Ecosystem


A sophisticated malware distribution campaign is exploiting compromised GitHub authentication tokens to systematically inject malicious code into hundreds of Python repositories. The attack, dubbed GlassWorm, represents a direct assault on software supply chain security by leveraging stolen developer credentials to gain write access to projects across the open-source ecosystem.


## The Threat


Security researchers at StepSecurity have identified an ongoing attack that transforms legitimate GitHub repositories into malware distribution channels. The campaign uses stolen authentication tokens to bypass access controls and inject obfuscated malicious code directly into source repositories, allowing attackers to compromise any developer who pulls and executes the affected code.


The breadth of the campaign is concerning: threat actors are targeting a wide spectrum of Python projects spanning multiple domains—from web frameworks to data science tools to containerized applications. This horizontal attack strategy maximizes the potential infection footprint and suggests the campaign is designed for scale rather than precision targeting of specific victims.


## Attack Mechanism


The operational approach is straightforward but effective. Attackers begin with stolen GitHub personal access tokens or OAuth credentials, obtained through prior breach activity, phishing campaigns, or other credential harvesting methods. Armed with these valid authentication credentials, they gain write permissions to compromised repositories without triggering alerts that might accompany account takeover attempts.


Once repository access is obtained, the attackers execute force-push operations that overwrite repository history with malicious versions. This technique is significant because it can obscure the attack from casual inspection—developers reviewing recent commits may not immediately recognize forced history as anomalous, particularly if the malicious changes are small or appended to legitimate files.


The actual payload delivery relies on code injection into initialization and entry-point files:


  • setup.py — Python package installation and configuration scripts
  • main.py — Primary application entry points
  • app.py — Web application bootstraps (commonly used in Flask, Streamlit, and Django projects)

  • The injected code is deliberately obfuscated to evade both automated scanning tools and manual code review. This obfuscation likely employs string encoding, dynamic execution primitives, or bytecode manipulation—techniques that complicate static analysis while remaining functionally transparent to runtime environments.


    ## Affected Ecosystems


    The attack targets a striking variety of Python application categories:


    Web Frameworks — Django applications and other web-based Python projects represent high-value targets due to their exposure to end users and the sensitive operations they frequently perform.


    Machine Learning Infrastructure — Research codebases and ML experimentation projects are particularly vulnerable because developers often execute code in trusted environments with minimal isolation or sandboxing.


    Data Visualization Tools — Streamlit dashboards and similar data application frameworks have become increasingly prevalent, making them attractive vectors for reaching data scientists and analysts.


    Package Distribution — Compromised packages on PyPI (Python Package Index) can achieve near-total propagation through the ecosystem, as package managers automatically pull and install updated versions for downstream dependents.


    This multi-domain approach indicates attackers understand that different categories of Python code reach different user populations. A compromised data science library affects researchers; a compromised web framework affects production deployments; a compromised utility affects both.


    ## Technical Approach and Execution


    The use of force-push operations merits closer examination. Standard Git workflows record commit history and typically alert repository maintainers to suspicious rewrites. Force-push bypasses these protections entirely when attackers possess valid authentication credentials. Unlike account compromise attempts that might generate unusual login alerts, credential-based access appears legitimate to GitHub's audit logging.


    The obfuscation strategy further compounds detection challenges. Clear-text malicious imports or system calls would trigger both automated code scanning (both on GitHub and in security tools developers use locally) and human reviewers. Obfuscated payloads evade signature-based detection and require deeper analysis to understand malicious intent.


    The targeting of common entry-point files—setup.py, main.py, and app.py—ensures that malicious code executes early in the application lifecycle, before defensive measures can be deployed. Payload execution during installation (setup.py) or application initialization (app.py) grants attackers early control over process behavior.


    ## Implications for the Python Ecosystem


    This campaign demonstrates a critical vulnerability in how the open-source community manages access control and code integrity. While GitHub provides security features like branch protection, required code review, and push notifications, these protections fail completely once legitimate authentication credentials are compromised.


    The Python ecosystem is particularly exposed because:


  • High trust dependency chains — Python developers frequently install packages with minimal scrutiny, trusting in community vetting that occurs asynchronously
  • Simple execution model — Python's interpreted nature means malicious code executes without compilation barriers or intermediate analysis steps
  • Development tool integration — Package managers integrate deeply with development environments, making injected code run with developer privileges

  • Developers who run affected repositories—whether pulling updates, executing installation routines, or invoking applications—face immediate compromise. The malware executes with whatever permissions the developer holds, potentially exposing API keys, database credentials, SSH keys, and source code stored in their working environment.


    ## Mitigation and Defensive Response


    Organizations and developers should implement immediate protective measures:


  • Audit GitHub personal access tokens — Identify and revoke any tokens created without clear justification; implement strict token rotation policies
  • Enable branch protection rules — Require pull request reviews and enforce restrictions on force-push operations for critical branches
  • Implement code signing — Use GPG-signed commits to cryptographically verify code origin and detect unsigned history rewrites
  • Deploy automated code scanning — Use GitHub's native code scanning features, third-party SAST tools, and dependency checkers before merging code
  • Isolate development environments — Use containerization or virtual machines to limit malware propagation if execution occurs
  • Monitor repository activity — Set up alerts for force-push operations, unusual collaborator additions, and suspicious commit patterns
  • Supply chain verification — Verify package checksums and signatures before installation; consider vendoring critical dependencies

  • ## HackWire Analysis


    GlassWorm illustrates a maturing threat model where attackers no longer target individual developers—they target the repositories themselves. By compromising credentials rather than accounts, attackers achieve persistence and scale while remaining invisible to standard account takeover detection. The campaign reveals that open-source security ultimately depends on credential hygiene; no amount of platform-level protection matters once valid tokens are stolen. The Python ecosystem's accessibility and trust-based dependency model, once its greatest strength for collaborative development, has become a liability against sophisticated supply chain attacks. Defense requires a fundamental shift toward cryptographic verification, behavioral monitoring, and segmentation of trust boundaries at the development environment level.