Close Menu

    Subscribe to Updates

    Get the latest news from tastytech.

    What's Hot

    The Government Just Released a Batch of UFO Files: Where Are the Aliens?

    May 9, 2026

    Gundam Breaker 4 Review – Steam Deck, Switch, and PS5 Tested – TouchArcade

    May 8, 2026

    10 Near-Perfect Sci-Fi Movies of the Last 6 Years, Ranked

    May 8, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    tastytech.intastytech.in
    Subscribe
    • AI News & Trends
    • Tech News
    • AI Tools
    • Business & Startups
    • Guides & Tutorials
    • Tech Reviews
    • Automobiles
    • Gaming
    • movies
    tastytech.intastytech.in
    Home»Tech Reviews»Self-propagating malware poisons open source software and wipes Iran-based machines
    Self-propagating malware poisons open source software and wipes Iran-based machines
    Tech Reviews

    Self-propagating malware poisons open source software and wipes Iran-based machines

    gvfx00@gmail.comBy gvfx00@gmail.comMarch 24, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    In an email, Aikido researcher Charlie Eriksen said the canister was taken down Sunday night and is no longer available.

    “It wasn’t as reliable/untouchable as they expected,” Eriksen wrote. “But for a while, it would have wiped systems if infected.”

    Like previous TeamPCP malware, CanisterWorm, as Aikido has named the malware, targets organizations’ CI/CD pipelines used for rapid development and deployment of software.

    “Every developer or CI pipeline that installs this package and has an npm token accessible becomes an unwitting propagation vector,  Eriksen wrote. “Their packages get infected, their downstream users install those, and if any of them have tokens, the cycle repeats.”

    As the weekend progressed, CanisterWorm was updated to add an additional payload: a wiper that targets machines exclusively in Iran. When the updated worm infects machines, it checks if the machine is in the Iranian timezone or is configured for use in that country. When either condition was met, the malware no longer activated the credential stealer and instead triggered a novel wiper that TeamPCP developers named Kamikaze. Eriksen said in an email that there’s no indication yet that the worm caused actual damage to Iranian machines, but that there was “clear potential for large-scale impact if it achieves active spread.”

    Eriksen said Kamikaze’s “decision tree is simple and brutal.”

    • Kubernetes + Iran: Deploy a DaemonSet that wipes every node in the cluster
    • Kubernetes + elsewhere: Deploy a DaemonSet that installs the CanisterWorm backdoor on every node
    • No Kubernetes + Iran: rm -rf / --no-preserve-root
    • No Kubernetes + elsewhere: Exit. Nothing happens.

    TeamPCP’s targeting of a country that the US is currently at war with is a curious choice. Up to now the group’s motivation has been financial gain. With no clear connection to monetary profit, the wiper seems out of character for TeamPCP. Eriksen said Aikido still doesn’t know the motive. He wrote:

    While there may be an ideological component, it could just as easily be a deliberate attempt to draw attention to the group. Historically, TeamPCP has appeared to be financially motivated, but there are signs that visibility is becoming a goal in itself. By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal.

    Table of Contents

    Toggle
    • The hack that keeps on giving
      • Related posts:
    • Kalshi suspended three political candidates from its platform for insider trading
    • AI models can acquire backdoors from surprisingly few malicious documents
    • The 181 best Cyber Monday deals, picked by tech and savings experts

    The hack that keeps on giving

    Last week’s supply-chain compromise of Trivy was made possible by a previous compromise of Aqua Security in late February. Although the company’s incident response was intended to replace all compromised credentials, the rotation was incomplete, allowing TeamPCP to take control of the GitHub account for distributing the vulnerability scanner. Aqua Security said it was performing a more thorough credential purge in response.

    Related posts:

    From NBN 25 to NBN 1000, Flip now has the cheapest NBN plans in multiple tiers

    Today's NYT Mini Crossword Answers for April 11

    Peacock will be the first streaming service with Dolby Vision 2 HDR and next-gen Atmos audio encodin...

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘NBA 2K25 Arcade Edition’ Headlines October 2024’s New Apple Arcade Releases With Three App Store Greats
    Next Article Top 5 Free Google Certificate Courses in 2026
    gvfx00@gmail.com
    • Website

    Related Posts

    Tech Reviews

    The Government Just Released a Batch of UFO Files: Where Are the Aliens?

    May 9, 2026
    Tech Reviews

    One of my top gaming headset picks just got a new level of personalization — Audeze’s ReSkin earcup covers let you ‘bring flair and personality’ to your headset

    May 8, 2026
    Tech Reviews

    Mozilla says 271 vulnerabilities found by Mythos have “almost no false positives”

    May 8, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025143 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 202575 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202574 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from tastytech.

    About Us
    About Us

    TastyTech.in brings you the latest AI, tech news, cybersecurity tips, and gadget insights all in one place. Stay informed, stay secure, and stay ahead with us!

    Most Popular

    Black Swans in Artificial Intelligence — Dan Rose AI

    October 2, 2025143 Views

    Every Clue That Tony Stark Was Always Doctor Doom

    October 20, 202575 Views

    We let ChatGPT judge impossible superhero debates — here’s how it ruled

    December 31, 202574 Views

    Subscribe to Updates

    Get the latest news from tastytech.

    Facebook X (Twitter) Instagram Pinterest
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 TastyTech. Designed by TastyTech.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.