Sponsor of the Day:
Jerkmate
https://circleid.com/posts/iran-targeted-by-self-propagating-malware-in-supply-chain-cyberattacks
Iran Targeted by Self-Propagating Malware in Supply-Chain Cyberattacks
Self-propagating malware hidden in open-source software is targeting Iranian systems, wiping data on infected machines while sparing others, signalling a shift...
iran targetedself propagatingsupply chainmalwarecyberattacks
https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks.
supply chain wormself propagatingnpm packageshijackssteal
https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise
Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm
Apr 23, 2026 - Malware found in @bitwarden/cli v2026.4.0 steals SSH keys, cloud secrets, and AI coding tool credentials, then spreads through victims' own npm packages....
compromised bitwarden clishai huludself propagatingnpm wormback