Threats Tagged 'worm'
View all threats tagged with 'worm'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'worm'
Click on any threat for detailed analysis and mitigation recommendations
A new Mini Shai-Hulud worm variant named Trinitite was detected targeting the npm package @7nohe/openapi-react-query-codegen. The attacker exploited a GitHub workflow vulnerability allowing any user to trigger npm publish via pull-request comments, resulting in rapid publication of malicious package versions. The worm uses obfuscation techniques to execute even when scripts are disabled, steals credentials from multiple developer and cloud platforms, and exfiltrates data via GitHub commits. It establishes persistence through systemd services and includes a destructive token revoke mechanism that can wipe user directories. This campaign is linked to the TeamPCP threat actor and appeared shortly after arrests of related suspects in Australia. Join the discussion | AlienVault OTX General | 08/31/2026, 15:26:41 UTC Added: 09/01/2026, 08:37:15 UTC |
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity. Join the discussion | AlienVault OTX General | 07/29/2026, 08:57:13 UTC Added: 07/29/2026, 11:52:25 UTC |
The Intercom TypeScript Library version 7.0.4 has been compromised with malicious code that harvests GitHub credentials. Upon installation, the package executes a preinstall hook that downloads the Bun runtime, then runs a payload to extract GitHub credentials using the gh auth token command. The attack employs sophisticated C2 communication by querying GitHub's commit search API for specific strings embedded in public repositories, effectively using legitimate services to evade detection. The attack patterns mirror previous Shai-Hulud compromises, which exhibit worm-like behavior by automatically using stolen credentials to infect additional npm packages. With 361,510 weekly downloads, this compromise poses significant risk for a widespread infection wave similar to November 2025 when over 1,000 packages were affected. Join the discussion | AlienVault OTX General | 07/24/2026, 01:19:11 UTC Added: 07/24/2026, 10:37:10 UTC |
Malicious npm packages associated with Namastex.ai were compromised with malware exhibiting tradecraft similar to TeamPCP's CanisterWorm campaign. The attack targeted packages including @automagik/genie and pgserve, implementing install-time execution that harvests credentials, environment variables, SSH keys, cloud credentials, browser data, and crypto-wallet artifacts. The payload exfiltrates stolen data to both a conventional webhook at telemetry.api-monitor.com and an Internet Computer Protocol canister endpoint. It incorporates self-propagation logic to compromise additional npm packages using stolen publishing tokens and includes cross-ecosystem spreading capabilities targeting PyPI. The malware uses hybrid encryption with RSA and AES-256-CBC for data exfiltration. Multiple package namespaces were affected, suggesting shared infrastructure or coordinated compromise across publisher accounts. Join the discussion | AlienVault OTX General | 04/22/2026, 16:22:18 UTC Added: 04/23/2026, 09:21:02 UTC |
An active supply chain worm campaign, dubbed SANDWORM_MODE, is spreading through typosquatting and AI toolchain poisoning across at least 19 malicious npm packages. The worm exhibits Shai-Hulud characteristics, incorporating GitHub API exfiltration with DNS fallback, hook-based persistence, SSH propagation, and MCP server injection targeting AI coding assistants. It harvests credentials from developer and CI environments, exfiltrates data via multiple channels, and uses stolen identities to propagate. The campaign also includes a weaponized GitHub Action for CI secret harvesting. The worm employs a multi-stage design with obfuscated loaders, time-gated execution, and extensive configuration options. It targets high-traffic developer utilities, crypto tooling, and AI coding tools, posing a significant threat to the software supply chain. Join the discussion | AlienVault OTX General | 02/23/2026, 10:04:22 UTC Added: 02/23/2026, 10:16:19 UTC |
The Boto Cor-de-Rosa campaign reveals Astaroth's new strategy of exploiting WhatsApp Web for propagation. This Brazilian banking malware now uses a Python-based worm module to retrieve victims' WhatsApp contact lists and automatically send malicious messages, expanding its infection reach. The attack begins with a malicious ZIP file sent via WhatsApp, containing a Visual Basic script that downloads additional components. The malware then operates two parallel modules: a propagation module for spreading through WhatsApp contacts, and a banking module for credential stealing. This campaign demonstrates Astaroth's evolution, combining traditional malware techniques with sophisticated social engineering and multi-platform propagation, primarily targeting Brazilian users. Join the discussion | AlienVault OTX General | 01/08/2026, 18:12:03 UTC Added: 01/09/2026, 09:26:35 UTC |
Shai-Hulud V2 is an advanced malware campaign targeting the npm software supply chain, compromising over 700 npm packages and creating more than 27,000 malicious GitHub repositories. It introduces sophisticated techniques including pre-install phase execution, persistent backdoors via self-hosted GitHub Actions runners, credential harvesting and recycling across victims, and a destructive failsafe mechanism. The malware exfiltrates data through GitHub and propagates within the npm ecosystem, also exploiting Azure DevOps build agents. This supply chain attack enables persistent remote code execution and widespread credential theft without requiring user interaction. European organizations relying on npm packages and GitHub Actions for CI/CD pipelines face significant risks of data breaches, system compromise, and operational disruption. Mitigation requires enhanced supply chain security practices, strict GitHub Actions runner controls, credential hygiene, and proactive monitoring for anomalous activity. Countries with strong software development sectors and high npm usage, such as Germany, France, the UK, and the Netherlands, are particularly vulnerable. Given its broad impact and advanced persistence mechanisms, the threat severity is assessed as high. Join the discussion | AlienVault OTX General | 12/03/2025, 08:47:16 UTC Added: 12/03/2025, 11:01:25 UTC |
Shai-Hulud 2.0 is a highly aggressive and automated supply-chain malware targeting the npm ecosystem, identified in November 2025. It rapidly compromises hundreds of npm packages within hours, behaving like a worm that harvests credentials and cloud secrets. The malware leverages GitHub Actions as a persistent backdoor and creates public repositories to exfiltrate stolen data. This attack represents a significant escalation in supply-chain attack sophistication, affecting major projects and organizations globally. It results in tens of thousands of attacker-created GitHub repositories, facilitating widespread propagation. The malware automates spreading to new npm accounts, increasing infection speed and scale. It does not require user interaction once initial compromise occurs and exploits trusted software supply chains. No CVE or patch is currently available, and no known exploits in the wild have been reported yet. The attack’s medium severity rating may underestimate its potential impact given its worm-like behavior and credential theft capabilities. Join the discussion | AlienVault OTX General | 11/27/2025, 03:00:54 UTC Added: 11/27/2025, 08:54:23 UTC |
Tangerine Turkey is a cryptomining campaign that propagates via VBScript worms spread through USB drives, leveraging legitimate system binaries for execution and persistence. The malware employs advanced defense evasion techniques such as registry modification and masquerading malicious files as legitimate system components. It establishes persistence through malicious services and scheduled tasks while attempting to disable Windows Defender. Although its primary objective is unauthorized cryptocurrency mining, its capabilities for persistence and lateral movement pose broader security risks. The campaign uses living-off-the-land binaries and creates mock directories to conceal its activities. No known CVEs or exploits are currently associated with this threat. The medium severity rating reflects the financial motivation and potential for system compromise without immediate destructive impact. European organizations using Windows systems with USB access are at risk, especially those with lax endpoint security controls and high-value targets. Mitigation requires targeted controls beyond generic advice, including USB device management, monitoring for living-off-the-land abuse, and registry integrity checks. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:29 UTC Added: 10/29/2025, 20:13:19 UTC |
GlassWorm is a groundbreaking self-propagating worm targeting VS Code extensions on OpenVSX marketplace. It employs invisible Unicode characters to conceal malicious code and utilizes a blockchain-based command and control infrastructure on Solana. The worm compromised seven OpenVSX extensions with 35,800 downloads, harvesting NPM, GitHub, and Git credentials, targeting cryptocurrency wallets, deploying SOCKS proxy servers, and installing hidden VNC servers. It spreads exponentially through the developer ecosystem using stolen credentials. The worm employs a triple-layer C2 setup involving Solana blockchain, direct IP connection, and Google Calendar. A new infected extension was also detected in Microsoft's VSCode marketplace. The campaign remains active, necessitating immediate security measures and audits of installed extensions. Join the discussion | AlienVault OTX General | 10/21/2025, 16:50:52 UTC Added: 10/21/2025, 19:24:05 UTC |
Showing 1 to 10 of 14 results