Robuta

Sponsor of the Day: Jerkmate
https://circleid.com/posts/iran-targeted-by-self-propagating-malware-in-supply-chain-cyberattacks Iran Targeted by Self-Propagating Malware in Supply-Chain Cyberattacks Self-propagating malware hidden in open-source software is targeting Iranian systems, wiping data on infected machines while sparing others, signalling a shift... iran targetedself propagatingsupply chainmalwarecyberattacks https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks. supply chain wormself propagatingnpm packageshijackssteal https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm Apr 23, 2026 - Malware found in @bitwarden/cli v2026.4.0 steals SSH keys, cloud secrets, and AI coding tool credentials, then spreads through victims' own npm packages.... compromised bitwarden clishai huludself propagatingnpm wormback