Skip to content
Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Hideo Kojima Shares New Screenshot Of Upcoming Horror Game OD

    June 23, 2026

    Yes (2025) by Nadav Lapid

    June 23, 2026

    The S58-Based M4 GT3 Motor

    June 23, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Self-propagating malware poisons open source software and wipes Iran-based machines
    Self-propagating malware poisons open source software and wipes Iran-based machines
    Tech Reviews

    Self-propagating malware poisons open source software and wipes Iran-based machines

    gvfx00@gmail.comBy gvfx00@gmail.comMarch 24, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    In an email, Aikido researcher Charlie Eriksen said the canister was taken down Sunday night and is no longer available.

    “It wasn’t as reliable/untouchable as they expected,” Eriksen wrote. “But for a while, it would have wiped systems if infected.”

    Like previous TeamPCP malware, CanisterWorm, as Aikido has named the malware, targets organizations’ CI/CD pipelines used for rapid development and deployment of software.

    “Every developer or CI pipeline that installs this package and has an npm token accessible becomes an unwitting propagation vector,  Eriksen wrote. “Their packages get infected, their downstream users install those, and if any of them have tokens, the cycle repeats.”

    As the weekend progressed, CanisterWorm was updated to add an additional payload: a wiper that targets machines exclusively in Iran. When the updated worm infects machines, it checks if the machine is in the Iranian timezone or is configured for use in that country. When either condition was met, the malware no longer activated the credential stealer and instead triggered a novel wiper that TeamPCP developers named Kamikaze. Eriksen said in an email that there’s no indication yet that the worm caused actual damage to Iranian machines, but that there was “clear potential for large-scale impact if it achieves active spread.”

    Eriksen said Kamikaze’s “decision tree is simple and brutal.”

    • Kubernetes + Iran: Deploy a DaemonSet that wipes every node in the cluster
    • Kubernetes + elsewhere: Deploy a DaemonSet that installs the CanisterWorm backdoor on every node
    • No Kubernetes + Iran: rm -rf / --no-preserve-root
    • No Kubernetes + elsewhere: Exit. Nothing happens.

    TeamPCP’s targeting of a country that the US is currently at war with is a curious choice. Up to now the group’s motivation has been financial gain. With no clear connection to monetary profit, the wiper seems out of character for TeamPCP. Eriksen said Aikido still doesn’t know the motive. He wrote:

    While there may be an ideological component, it could just as easily be a deliberate attempt to draw attention to the group. Historically, TeamPCP has appeared to be financially motivated, but there are signs that visibility is becoming a goal in itself. By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal.

    Table of Contents

    Toggle
    • The hack that keeps on giving
      • Related posts:
    • Lumus brought a massively wider FOV to smartglasses at CES 2026
    • ASUS RT-BE58 Go: A Solid Wi-Fi 7 Travel Router
    • What legacy business intelligence technology can learn from video games

    The hack that keeps on giving

    Last week’s supply-chain compromise of Trivy was made possible by a previous compromise of Aqua Security in late February. Although the company’s incident response was intended to replace all compromised credentials, the rotation was incomplete, allowing TeamPCP to take control of the GitHub account for distributing the vulnerability scanner. Aqua Security said it was performing a more thorough credential purge in response.

    Related posts:

    Google Is Currently Struggling To Define Words Like Disregard, Stop And Ignore

    Trump Mobile Phone Review: My Long Weekend With The Golden T1

    Watch this – the latest humanoid robots are both unnervingly sassy and comfortingly error-prone

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘NBA 2K25 Arcade Edition’ Headlines October 2024’s New Apple Arcade Releases With Three App Store Greats
    Next Article Top 5 Free Google Certificate Courses in 2026
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Meta Is ‘Pausing’ Employee Tracking Program After It Let The Whole Company See Sensitive Data

    June 23, 2026
    Tech Reviews

    Using AI Companion Apps Gives Many Singles the Ick, Survey Finds

    June 22, 2026
    Tech Reviews

    After 19 years, Google Street View has finally added a ‘beautiful’, long-awaited country — and Geoguessr fans are calling it a ‘great addition’ to the geography game

    June 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025205 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025129 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202599 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025205 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 2025129 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202599 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.