- react-native-country-select v0.3.91Compromised npm package with malicious preinstall hook, part of ForceMemo campaign
- GlassWormPrimary malware campaign targeting developers via VS Code extensions and GitHub account takeovers
- ForceMemoNew GlassWorm variant using force-push technique to inject malware into Python repos
- react-native-international-phone-number v0.11.8Compromised npm package with preinstall hook delivering obfuscated malware
ThreatNoir Morning Brief — March 17
Morning Review in IT Security — March 17, 2026
The cybersecurity landscape continues to face significant threats across multiple vectors on March 17, 2026. From supply chain compromises targeting open-source repositories to active exploitation of critical infrastructure vulnerabilities, security teams face an escalating array of challenges. Today's briefing covers emerging malware campaigns, government infrastructure attacks, and ongoing incidents affecting major organizations worldwide.
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
A sophisticated malware campaign known as GlassWorm is leveraging stolen GitHub tokens to inject malicious code into hundreds of Python repositories. The attack specifically targets Python projects including Django applications, machine learning research code, Streamlit dashboards, and PyPI packages by appending obfuscated code to critical files such as setup.py, main.py, and app.py. According to security researchers at StepSecurity, the campaign represents a significant threat to the open-source ecosystem. Source: GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
CISA Flags Wing FTP Server Flaw as Actively Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency has issued warnings to U.S. government agencies regarding active exploitation of vulnerabilities in Wing FTP Server. The flaws can be chained together to enable remote code execution attacks against affected systems. CISA has added evidence of active exploitation to its Known Exploited Vulnerabilities catalog, prompting immediate remediation efforts across federal agencies. Source: CISA flags Wing FTP Server flaw as actively exploited in attacks
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA added a medium-severity information disclosure vulnerability affecting Wing FTP to its Known Exploited Vulnerabilities catalog on Monday, citing confirmed active exploitation. The vulnerability, tracked as CVE-2025-47813 with a CVSS score of 4.3, leaks the installation path of the application under certain conditions. This disclosure flaw can provide attackers with critical information needed to chain with other vulnerabilities for more severe attacks. Source: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
Stryker Attack Wiped Tens of Thousands of Devices, No Malware Needed
Medical technology giant Stryker fell victim to a cyberattack last week that remotely wiped tens of thousands of employee devices without requiring traditional malware deployment. The incident was confined to Stryker's internal Microsoft environment, demonstrating how attackers can leverage legitimate administrative capabilities to cause widespread damage. The attack highlights the critical importance of identity and access management controls in preventing catastrophic device loss. Source: Stryker attack wiped tens of thousands of devices, no malware needed
FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft
The Federal Bureau of Investigation has warned gamers about malware hidden within several Steam games that stole browser data and drained cryptocurrency wallets. The malicious activity occurred between May 2024 and January 2026, affecting an unknown number of gaming platform users. The compromise demonstrates the ongoing risk of supply chain attacks through legitimate distribution channels targeting consumer-level systems. Source: FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft
China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years
Researchers have uncovered an extensive cyberespionage campaign involving China-linked threat actors who maintained persistent access to Southeast Asian military organizations over extended periods. The campaign employed novel backdoors alongside familiar evasion techniques to evade detection and sustain long-term presence within regional defense networks. The discovery underscores the persistent nature of state-sponsored cyber operations targeting critical infrastructure in the region. Source: China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years
Help on the Line: How a Microsoft Teams Support Call Led to Compromise
Microsoft's Detection and Response Team investigated a voice phishing attack conducted through Microsoft Teams that resulted in organizational compromise. The incident demonstrates how threat actors exploit trusted communication tools and social engineering tactics to facilitate identity-led intrusions. The investigation provides critical insights into attack methodologies and defensive measures organizations can implement to prevent similar incidents. Source: Help on the line: How a Microsoft Teams support call led to compromise
Threat Actor Selling Kordon Database from Russian Federal Border Service
A threat actor is allegedly offering the Kordon database, allegedly compromised from the Russian Federal Border Service in September 2023, for sale on underground forums. The database reportedly contains over 1 billion total records covering 79.5 million unique individuals, including foreign nationals. The potential compromise represents a significant privacy and national security concern given the sensitive nature of border service data. Source: ‼️🇷🇺 A threat actor is allegedly selling the "Kordon" database from the Russian Federal Border Service
Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact
Four major corporations—Broadcom, Bechtel, Estée Lauder, and Abbott Technologies—remain silent regarding their potential exposure to the Oracle Enterprise Business Suite zero-day vulnerability exploitation. The Cl0p ransomware group has been linked to the attacks leveraging these critical vulnerabilities. Most other affected organizations have issued public statements regarding their security posture and remediation efforts. Source: Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact
UK's Companies House Confirms Security Flaw Exposed Business Data
Companies House, the British government agency responsible for the registry of all United Kingdom companies, confirmed that a security flaw in its WebFiling service exposed company information since October 2025. The service was taken offline on Friday to remediate the vulnerability and has since been restored to operational status. The incident raises concerns about the security of critical government business registration infrastructure. Source: UK's Companies House confirms security flaw exposed business data
Security teams should prioritize patching Wing FTP Server vulnerabilities, reviewing GitHub token access controls, auditing Microsoft Teams security configurations, and verifying their organizations' exposure to Oracle EBS zero-day exploits. The convergence of supply chain attacks, active exploitation of known vulnerabilities, and sophisticated state-sponsored campaigns underscores the need for comprehensive threat intelligence integration and rapid incident response capabilities.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Information disclosure vulnerability in Wing FTP Server allowing discovery of local installation path via long UID cookie value
- Critical remote code execution vulnerability in Wing FTP Server exploited in the wild
- Information disclosure vulnerability in Wing FTP Server allowing password theft
- Information disclosure vulnerability in Wing FTP Server affecting versions prior to 7.4.4; leaks installation paths via malformed UID cookie
- Critical remote code execution vulnerability in Wing FTP Server (CVSS 10.0); patched in version 7.4.4
- HandalaIran-linked hacktivist group claiming responsibility for Stryker attack; used wiper functionality via Intune rather than traditional malware
- LampyMalicious Steam game distributing data-stealing malware
- LunaraMalicious Steam game distributing data-stealing malware
- PirateFiMalicious Steam game distributing data-stealing malware
- ChemiaMalicious Steam game distributing data-stealing malware
- TokenovaMalicious Steam game distributing data-stealing malware
- BlockBlastersMalicious Steam game; estimated $150,000 in community losses
- DashverseMalicious Steam game also known as DashFPS distributing data-stealing malware
- KordonDatabase allegedly stolen from Russian Federal Border Service
- Unspecified zero-day flaws in Oracle E-Business Suite exploited to access victim data for extortion
- Threat actor cluster suspected by cybersecurity community of driving the Oracle EBS exploitation campaign
- Cl0pRansomware and extortion group claiming responsibility for Oracle EBS campaign; believed to be public-facing brand for operation potentially driven by FIN11