GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

2026-03-17T01:24:14Z8d8dcc9d8ad81218512e9512d9d2571d76d2ab89b7c0e2ce09761ee033a6fa2e
AI-agentAppArmorCVE-2025-68613CVE-2026-21666CVE-2026-21667CVE-2026-3909ClickFixCrackArmorGitHub-tokensGlassWormMacSyncOpen-VSXOpenClawPythonSocksEscort','botnet'chromedata-exfiltrationmacOSmalwaren8nprivilege-escalationsupply-chainsupply-chain-attackveeampatchzero-day

What happened

A burst of high-impact activity across supply‑chain, browser, and infrastructure vectors: the GlassWorm campaign is using stolen GitHub tokens to force‑push obfuscated malware into hundreds of Python projects and is now abusing Open VSX (72 extensions) for transitive propagation. Multiple actively exploited and critical flaws were disclosed or patched this week, including Chrome zero‑days (e.g., CVE‑2026‑3909), Veeam Backup & Replication RCEs (CVE‑2026‑21666, CVE‑2026‑21667), and a widely exploited n8n expression‑injection RCE (CVE‑2025‑68613). Qualys’ “CrackArmor” AppArmor vulnerabilities can

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
8d8dcc9d8ad81218512e9512d9d2571d76d2ab89b7c0e2ce09761ee033a6fa2e
Enrichment time
2026-03-17T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.