Self-propagating malware poisons open source software and wipes Iran-based machines

Self-propagating malware poisons open source software and wipes Iran-based machines

A newly identified hacking group has launched an aggressive campaign on the internet, deploying a self-replicating backdoor alongside a data-wiping malware specifically aimed at machines in Iran. This group, known as TeamPCP, first came to light in December when security researchers from Flare observed them unleashing a worm targeting inadequately secured cloud-hosted platforms. The primary goal of TeamPCP is to establish a distributed network for proxy services and scanning, later exploiting compromised servers for data exfiltration, ransomware deployment, extortion, and cryptocurrency mining. The group's expertise lies in large-scale automation and the integration of established attack methodologies. Recently, TeamPCP intensified its operations, employing constantly evolving malware that significantly increases its control over various systems. Last week, they executed a supply-chain attack that compromised nearly all versions of the popular Trivy vulnerability scanner by breaching the GitHub account of Aqua Security, the entity behind Trivy. Over the weekend, researchers noted that TeamPCP was deploying sophisticated malware capable of self-propagation, enabling it to infect new machines without any user interaction. Once a device is compromised, the malware seeks out access tokens for the npm repository and modifies any available publishable packages by injecting malicious code into new versions. Notably, Aikido reported that the worm targeted 28 different packages in a mere 60 seconds. While earlier iterations required manual distribution, the latest updates have automated this process, expanding the worm's reach dramatically. The malware employs a unique, tamper-resistant control mechanism utilizing an Internet Computer Protocol-based canister, which functions as a self-executing smart contract that is impervious to external alterations. This allows the attackers to direct the worm to ever-changing URLs for hosting malicious binaries, enabling continual adjustments to their control infrastructure. Infected machines are designed to report back to the canister every 50 minutes, ensuring the attackers maintain ongoing control.

Sources : Ars Technica

Published On : Mar 24, 2026, 12:40

Computing
Market Turbulence: Four Key Factors Impacting Stocks This Week

This past week has been challenging for the stock market, driven by several significant forces that have created turbule...

CNBC | Jul 25, 2026, 20:05
Market Turbulence: Four Key Factors Impacting Stocks This Week
AI
Revolutionizing Office Automation: Prentis Aims to Secure $100 Million in Funding

Prentis, a newly established AI research lab, is making waves in the tech industry as it prepares to raise $100 million ...

TechCrunch | Jul 25, 2026, 24:00
Revolutionizing Office Automation: Prentis Aims to Secure $100 Million in Funding
Science
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges

In a groundbreaking move to address the critical issue of renewable energy intermittency, a small town in southern Finla...

CNBC | Jul 25, 2026, 05:35
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges
Space
SpaceX Successfully Tests Starship Rocket, Launching New Era of Space Exploration

On Friday evening, SpaceX executed a significant milestone by launching its colossal Starship rocket from its facility i...

CNBC | Jul 25, 2026, 24:10
SpaceX Successfully Tests Starship Rocket, Launching New Era of Space Exploration
Computing
Reclaiming Control: Librarians Host Workshops to Help People Navigate AI Tools

In a lively library setting in South Philadelphia, Charlie Bailey, a local librarian, humorously noted, "Everybody’s on ...

TechCrunch | Jul 25, 2026, 16:20
Reclaiming Control: Librarians Host Workshops to Help People Navigate AI Tools
View All News