Self-propagating malware poisons open source software and wipes Iran-based machines



In an email, Aikido researcher Charlie Eriksen said the canister was taken down Sunday night and is no longer available.

“It wasn’t as reliable/untouchable as they expected,” Eriksen wrote. “But for a while, it would have wiped systems if infected.”

Like previous TeamPCP malware, CanisterWorm, as Aikido has named the malware, targets organizations’ CI/CD pipelines used for rapid development and deployment of software.

“Every developer or CI pipeline that installs this package and has an npm token accessible becomes an unwitting propagation vector,  Eriksen wrote. “Their packages get infected, their downstream users install those, and if any of them have tokens, the cycle repeats.”

As the weekend progressed, CanisterWorm was updated to add an additional payload: a wiper that targets machines exclusively in Iran. When the updated worm infects machines, it checks if the machine is in the Iranian timezone or is configured for use in that country. When either condition was met, the malware no longer activated the credential stealer and instead triggered a novel wiper that TeamPCP developers named Kamikaze. Eriksen said in an email that there’s no indication yet that the worm caused actual damage to Iranian machines, but that there was “clear potential for large-scale impact if it achieves active spread.”

Eriksen said Kamikaze’s “decision tree is simple and brutal.”

  • Kubernetes + Iran: Deploy a DaemonSet that wipes every node in the cluster
  • Kubernetes + elsewhere: Deploy a DaemonSet that installs the CanisterWorm backdoor on every node
  • No Kubernetes + Iranrm -rf / --no-preserve-root
  • No Kubernetes + elsewhere: Exit. Nothing happens.

TeamPCP’s targeting of a country that the US is currently at war with is a curious choice. Up to now the group’s motivation has been financial gain. With no clear connection to monetary profit, the wiper seems out of character for TeamPCP. Eriksen said Aikido still doesn’t know the motive. He wrote:

While there may be an ideological component, it could just as easily be a deliberate attempt to draw attention to the group. Historically, TeamPCP has appeared to be financially motivated, but there are signs that visibility is becoming a goal in itself. By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal.

The hack that keeps on giving

Last week’s supply-chain compromise of Trivy was made possible by a previous compromise of Aqua Security in late February. Although the company’s incident response was intended to replace all compromised credentials, the rotation was incomplete, allowing TeamPCP to take control of the GitHub account for distributing the vulnerability scanner. Aqua Security said it was performing a more thorough credential purge in response.



Source link

  • Related Posts

    This New Drone Spins So Fast The Human Eye Can Barely See It

    Researchers at Northwestern announced that they may have cracked the drone-invisibility-code. Dubbed the Phantom Twist by its creators, the drone exploits faults in human vision to become nearly invisible to the…

    Today’s NYT Mini Crossword Answers for Saturday, Aug. 1

    Need some help with today’s Mini Crossword? It’s a long one today. Read on for all the answers. Mini across clues and answers 1A clue: Coffee choice before bedAnswer: DECAF…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    WestJet cancels flights as Sunday strike deadline looms

    WestJet cancels flights as Sunday strike deadline looms

    Nadia Comaneci became a star at the 1976 Montreal Olympics. Now, she's back in Canada to be honoured: 'Imagine!'

    Nadia Comaneci became a star at the 1976 Montreal Olympics. Now, she's back in Canada to be honoured: 'Imagine!'

    United Taps Houston For “Elevated” 787-9 Expansion, Names 4 Long-Haul Destinations

    United Taps Houston For “Elevated” 787-9 Expansion, Names 4 Long-Haul Destinations

    Since Toronto’s renoviction bylaw took effect a year ago, calls about such evictions have 'all but disappeared'

    Since Toronto’s renoviction bylaw took effect a year ago, calls about such evictions have 'all but disappeared'

    The Republic of Korea and WHO discuss joint priorities, challenges and trends around global health

    The Republic of Korea and WHO discuss joint priorities, challenges and trends around global health

    George Santos Fined Over Bets on State of the Union on Kalshi Prediction Market

    George Santos Fined Over Bets on State of the Union on Kalshi Prediction Market