avatar
The Hacker News
@thehackernews
21.03.2026 12:30
⚠️ WARNING - A Trivy-linked supply chain attack has escalated into a self-propagating npm worm now spreading across dozens of packages.

It steals npm tokens, republishes itself, and spreads through developer machines and CI. Uses an ICP canister to rotate payloads and resist takedowns.

�� How the worm spreads and updates payloads → https://thehackernews.com/2026/03/trivy-supply-chain-attack-triggers-self.html
🔥 7
🤯 6
👍 4
1
😱 1
31 10.4K

Обсуждение 0

Обсуждение не доступно в веб-версии. Чтобы написать комментарий, перейдите в приложение Telegram.

Обсудить в Telegram

The Hacker News

162.3K
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Открыть в Telegram