Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    Self-propagating malware poisons open source software and wipes Iran-based machines

    March 24, 2026

    ‘NBA 2K25 Arcade Edition’ Headlines October 2024’s New Apple Arcade Releases With Three App Store Greats

    March 24, 2026

    The Animated Series Netflix Has Been Hiding Just Unleashed Its First Season 2 Trailer

    March 24, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Self-propagating malware poisons open source software and wipes Iran-based machines
    Self-propagating malware poisons open source software and wipes Iran-based machines
    Tech Reviews

    Self-propagating malware poisons open source software and wipes Iran-based machines

    gvfx00@gmail.comBy gvfx00@gmail.comMarch 24, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    In an email, Aikido researcher Charlie Eriksen said the canister was taken down Sunday night and is no longer available.

    “It wasn’t as reliable/untouchable as they expected,” Eriksen wrote. “But for a while, it would have wiped systems if infected.”

    Like previous TeamPCP malware, CanisterWorm, as Aikido has named the malware, targets organizations’ CI/CD pipelines used for rapid development and deployment of software.

    “Every developer or CI pipeline that installs this package and has an npm token accessible becomes an unwitting propagation vector,  Eriksen wrote. “Their packages get infected, their downstream users install those, and if any of them have tokens, the cycle repeats.”

    As the weekend progressed, CanisterWorm was updated to add an additional payload: a wiper that targets machines exclusively in Iran. When the updated worm infects machines, it checks if the machine is in the Iranian timezone or is configured for use in that country. When either condition was met, the malware no longer activated the credential stealer and instead triggered a novel wiper that TeamPCP developers named Kamikaze. Eriksen said in an email that there’s no indication yet that the worm caused actual damage to Iranian machines, but that there was “clear potential for large-scale impact if it achieves active spread.”

    Eriksen said Kamikaze’s “decision tree is simple and brutal.”

    • Kubernetes + Iran: Deploy a DaemonSet that wipes every node in the cluster
    • Kubernetes + elsewhere: Deploy a DaemonSet that installs the CanisterWorm backdoor on every node
    • No Kubernetes + Iran: rm -rf / --no-preserve-root
    • No Kubernetes + elsewhere: Exit. Nothing happens.

    TeamPCP’s targeting of a country that the US is currently at war with is a curious choice. Up to now the group’s motivation has been financial gain. With no clear connection to monetary profit, the wiper seems out of character for TeamPCP. Eriksen said Aikido still doesn’t know the motive. He wrote:

    While there may be an ideological component, it could just as easily be a deliberate attempt to draw attention to the group. Historically, TeamPCP has appeared to be financially motivated, but there are signs that visibility is becoming a goal in itself. By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal.

    Table of Contents

    Toggle
    • The hack that keeps on giving
      • Related posts:
    • US TP-Link Router Ban Saga: Where Exactly TP-Link Routers Are Made?
    • 'Shot in low light, these images require immense skill to get right' – see the Travel Photographer o...
    • OpenAI walks a tricky tightrope with GPT-5.1’s eight new personalities

    The hack that keeps on giving

    Last week’s supply-chain compromise of Trivy was made possible by a previous compromise of Aqua Security in late February. Although the company’s incident response was intended to replace all compromised credentials, the rotation was incomplete, allowing TeamPCP to take control of the GitHub account for distributing the vulnerability scanner. Aqua Security said it was performing a more thorough credential purge in response.

    Related posts:

    Letterboxd Video Store's first film rentals will be available this week

    Everything NVIDIA announced at CES 2026

    Microsoft warns of new “Payroll Pirate” scam stealing employees’ direct deposits

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘NBA 2K25 Arcade Edition’ Headlines October 2024’s New Apple Arcade Releases With Three App Store Greats
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    Ultrahuman opens US pre-orders for Ring Pro

    March 24, 2026
    Tech Reviews

    Today’s NYT Connections: Sports Edition Hints, Answers for March 24 #547

    March 24, 2026
    Tech Reviews

    ‘The feature was not a good feature’ — Grammarly CEO admits Experts Review didn’t work, but you may not like what replaces it

    March 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 202521 Views

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 202521 Views

    BMW Will Put eFuel In Cars Made In Germany From 2028

    October 14, 202511 Views

    Best Sonic Lego Deals – Dr. Eggman’s Drillster Gets Big Price Cut

    December 16, 20259 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.