vs-code-extensions

1 article
sort: new top best
clear filter
0 7/10

StepSecurity discovered ForceMemo, an ongoing campaign compromising hundreds of GitHub accounts via the GlassWorm malware (distributed through malicious VS Code/Cursor extensions) to inject obfuscated, Solana blockchain-based C2 malware into Python repositories. Attackers use stolen GitHub credentials to force-push malicious code while preserving original commit metadata, affecting popular projects like Django and ML research repositories.

StepSecurity ForceMemo GlassWorm GitHub Python PyPI Django Streamlit Solana Cursor VS Code amirasaran/django-restful-admin BierOne wecode-bootcamp-korea HydroRoll-Team
stepsecurity.io · varunsharma07 · 19 hours ago · details · hn