ended3월 24일· 1 sources

Self-propagating malware poisons open source software and wipes Iran-based machines

자가 전파 멀웨어, 오픈소스 소프트웨어를 오염시키고 이란 소재 시스템 데이터 삭제

Why it matters

A new hacking group called TeamPCP has been conducting a persistent campaign spreading self-propagating malware that poisons open-source packages and wipes data on Iran-based machines. The group compromised the Trivy vulnerability scanner via a supply-chain attack and deployed worm-enabled malware that automatically infects npm packages using stolen access tokens. The worm uses an Internet Computer Protocol-based canister as a tamper-proof command-and-control mechanism, allowing attackers to dynamically swap server URLs.

1
Sources
+0
24h
Growth
181d
Active
TeamPCPnpmsupply-chain attackTrivydata wiperself-propagating malware

Sources

Related Issues