#canisterworm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #canisterworm, aggregated by home.social.
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.
Last week's question was why the software ecosystem keeps shipping holes and handing the cleanup bill to operational teams. This week #npm answered, at least partially. npm v12 will block automatic code execution during install by default — no more preinstall scripts running silently, no more Git dependencies or URL-based packages pulling in whatever they feel like. Developers will have to explicitly opt in. It's the right call, it's what the supply chain attack surface has been screaming for across months of #CanisterWorm, Shai-Hulud, IronWorm, and Megalodon campaigns, and it arrives roughly four years after the attack pattern became impossible to ignore.
The #malware section this week is, as ever, the context that makes the fix legible. Nineteen PyPI packages trojaned via .pth startup hooks. A WinRAR flaw from last year still fueling active campaigns against Ukrainian organizations. #TeamPCP back with CanisterWorm. The backlog of techniques that predate npm v12 isn't going anywhere — and the install-time execution block doesn't touch the packages already in production, the developers who won't upgrade immediately, or the registries that aren't npm. It's a meaningful fix to a well-understood problem. It's also, by the industry's own timeline, a very belated one.
→ Week #24/2026 also covers: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and #ShinyHunters went after Oracle PeopleSoft at 100+ universities
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
npm Worm Targets Dev Environments, Exploits Supply Chain
A newly discovered npm malware attack has infected multiple packages, using sneaky tactics like install-time execution and credential theft to compromise developer environments and spread through the supply chain. This self-propagating malware strain appears to be targeting specialized developer workflows, putting a spotlight on vulnerabilities…
#MalwareOperations #SupplyChain #Npm #Canisterworm #DevEnvironments
-
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
CanisterWorm – kolejna kampania malware w ekosystemie npm
Badacze bezpieczeństwa z StepSecurity zidentyfikowali podejrzane aktualizacje wielu paczek npm. Okazuje się, że jest to nowa kampania – nazwana CanisterWorm – która nie tylko infekuje urządzenia programistów, ale też pakiety, do których mają oni dostęp (z poziomu swojego tokenu). Według ustaleń badaczy początkiem kampanii było wdrożenie złośliwej aktualizacji skanera Trivy,...
#WBiegu #Canisterworm #Malware #Npm
https://sekurak.pl/canisterworm-kolejna-kampania-malware-w-ekosystemie-npm/
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
‘CanisterWorm’ Springs #Wiper Attack #Targeting #Iran
A financially motivated data theft and #extortion group is attempting to inject itself into the #Iranwar , unleashing a #worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran’s time zone or have #Farsi set as the default language.
#security #CanisterWormhttps://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
The new CanisterWorm is spreading via npm, hijacking dev accounts and targeting Kubernetes, with a wiper that triggers on Iran-based systems
Read: https://hackread.com/canisterworm-kubernetes-clusters-kamikaze-wiper/
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
‘CanisterWorm’ Springs Wiper Attack Targeting Iran
https://krebsonsecurity.com/2026/03/canisterworm-springs-wiper-attack-targeting-iran/
#InternetComputerProtocol #Ne'er-Do-WellNews #ALittleSunshine #LatestWarnings #TheComingStorm #CatalinCimpanu #CharlieEriksen #AquaSecurity #CanisterWorm #Ransomware #AssafMorag #TeamPCP #Aikido #Flare #Trivy #ICP
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
https://winbuzzer.com/2026/03/23/trivy-breach-pushed-infostealer-via-github-actions-xcxwbn/
Trivy Breached Twice in a Month via GitHub Actions
#GitHub #GitHubActions #Cybersecurity #Malware #Cybercrime #SecurityBreach #OpenSource #Hackers #npm #Javascript #SoftwareDevelopment #CloudComputing #DataBreaches #Trivy #AquaSecurity #TeamPCP #CanisterWorm
-
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security -
#Trivy #SupplyChain Attack Spreads, Triggers Self-Spreading #CanisterWorm Across 47 #npm Packages
#security