#canisterworm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #canisterworm, aggregated by home.social.
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
npm Worm Targets Dev Environments, Exploits Supply Chain
A newly discovered npm malware attack has infected multiple packages, using sneaky tactics like install-time execution and credential theft to compromise developer environments and spread through the supply chain. This self-propagating malware strain appears to be targeting specialized developer workflows, putting a spotlight on vulnerabilities…
#MalwareOperations #SupplyChain #Npm #Canisterworm #DevEnvironments
-
📢 Campagne TeamPCP : compromission en chaîne de Trivy, KICS, LiteLLM et Telnyx via CI/CD
📝 ## 🔍 ContexteArticle publié le 2 avril 2026 (mis à jour le 8 avril) par Alessandro Brucato sur le blog de Tracebi...
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-campagne-teampcp-compromission-en-chaine-de-trivy-kics-litellm-et-telnyx-via-ci-cd/
🌐 source : https://tracebit.com/blog/detecting-cicd-supply-chain-attacks-with-canary-credentials
#CI_CD #CanisterWorm #Cyberveille -
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
----------------
🔎 Threat Intelligence
Summary
This report documents the TeamPCP supply‑chain campaign that began with a pull request to Aqua Security’s Trivy and escalated into a multi‑ecosystem compromise. The actor exploited a pull_request_target GitHub Actions workflow to extract an aqua‑bot Personal Access Token (PAT), then used that token to rewrite release tags and distribute attacker‑controlled Trivy scanner code.
Technical narrative
• Initial compromise: A pull_request_target workflow ran in the base repository context and exposed the aqua‑bot PAT. The token was later used for further actions.
• Tag rewriting: Adversaries force‑pushed nearly all release tags in aquasecurity/trivy-action, pointing tags to malicious commits rather than creating new branches or releases. Affected Trivy versions were observed as v0.69.4–v0.69.6 in Docker Hub images.
• Malicious payload behavior: The injected scanner code scanned process memory and filesystems for cached credentials, encrypted harvested data, exfiltrated to a typosquatted domain, then executed the legitimate Trivy binary so CI logs appeared normal.
• Persistence and C2: Malicious Docker images established a systemd service that polled Internet Computer Protocol (ICP) canisters for commands. Researchers characterized CanisterWorm as the first publicly documented malware using ICP canisters for command and control.
• Lateral spread and package compromise: Harvested credentials included npm auth tokens; the worm scanned for tokens and automatically published malicious package versions where tokens permitted. Dozens of npm packages and multiple scopes were compromised. Researchers also reported tag rewrites in Checkmarx KICS (35 tags rewritten) and downstream impacts across Docker Hub, npm, Open VSX Registry, and PyPI.Observed impact and attribution
• Actor: TeamPCP is credited with the campaign by multiple industry researchers.
• Scope: Mandiant CTO Charles Carmakal reported over 1,000 SaaS environments actively impacted, with a projection up to 10,000.
• Documentation: CrowdStrike, Wiz, and others have published detailed analyses referenced by this report.Notes
This summary focuses on the factual timeline, techniques, and observed artifacts described in the source material. The original post indicates an emphasis on detection logic for each kill‑chain phase but those detection rules are not reproduced here.
🔹 TeamPCP #Trivy #CanisterWorm #ICP_Canisters #SupplyChain
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security -
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security -
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security -
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security -
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security