ForceMemo in the DNS Spotlight

Several attacks tied to the ForceMemo campaign have targeted developers by compromising GitHub repositories and injecting malware into widely used Python projects. The activity, uncovered and tracked by StepSecurity, has affected hundreds of repositories since March 2026.

StepSecurity identified1 several IoCs associated with the campaign. After refining the dataset and removing legitimate infrastructure, we analyzed 20 IoCs comprising nine subdomains, five domains, and six IP addresses. Using our proprietary tools to further investigate the threat, we uncovered these findings:

  • One domain categorized as an IoC bulk-registered with 11 look-alike domains
  • One domain named as an IoC was likely registered with malicious intent
  • 86 email-connected domains found
  • Nine additional IP addresses uncovered, four already classified as malicious
  • 557 string-connected domains unearthed 

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push
Try our WhoisXML API for free
Get started