News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Mar 24, 2026 at 12:38 Big Tech

Self-propagating malware poisons open source software and wipes Iran-based machines

Development houses: It's time to check your networks for infections.

By Dan Goodin Original source
Self-propagating malware poisons open source software and wipes Iran-based machines

A new hacking group has been rampaging the Internet in a persistent campaign that spreads a self-propagating and never-before-seen backdoor—and curiously a data wiper that targets Iranian machines. The group, tracked under the name TeamPCP, first gained visibility in December, when researchers from security firm Flare observed it unleashing a worm that targeted cloud-hosted platforms that weren’t properly secured. The objective was to build a distributed proxy and scanning infrastructure and then use it to compromise servers for exfiltrating data, deploying ransomware, conducting extortion, and mining cryptocurrency. The group is notable for its skill in large-scale automation and integration of well-known attack techniques. Relentless and constantly evolving More recently, TeamPCP has waged a relentless campaign that uses continuously evolving malware to bring ever more systems under its control. Late last week, it compromised virtually all versions of the widely used Trivy vulnerability scanner in a supply-chain attack after gaining privileged access to the GitHub account of Aqua Security, the Trivy creator.Read full article Comments

Quick summary

TeamPCP, a newly identified hacking group, has deployed a self‑propagating backdoor and a data‑wiping component that specifically targets Iranian machines, initially spreading via a worm that compromised insecure cloud platforms and later compromising the Trivy vulnerability scanner through a GitHub account takeover of its creator, Aqua Security.

Related tags

Companies and people

Story threads

Continue with this story

Follow the same topic through connected articles, entity pages, and active story threads.

Ad slot

Article monetization slot

Reserved for contextual monetization inside article pages.

Explore options

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page