The Blog

Security insights, threat intelligence, and engineering deep-dives.

Supply Chain6 min read

axios Supply Chain Attack: 100M Weekly Downloads, One Hijacked Account

The npm account behind axios was compromised, injecting a cross-platform RAT into two malicious releases. Here's the full attack chain and what to check right now.

TT
Taco Team
Read
Supply Chain5 min read

TeamPCP Compromises Telnyx on PyPI Using WAV Steganography

The Telnyx Python SDK joined a growing list of packages poisoned by TeamPCP โ€” a campaign that hides malware payloads inside audio files using WAV steganography.

TT
Taco Team
Read
Threat Intel7 min read

CanisterWorm: The Kubernetes Wiper That Detects Its Targets by Timezone

TeamPCP's CanisterWorm delivers two completely different payloads depending on whether a cluster is Iranian. For Iran: total cluster destruction. For everyone else: a silent blockchain-C2 backdoor.

TT
Taco Team
Read
Threat Intel8 min read

CanisterWorm: How a Trivy Compromise Became a Self-Propagating npm Worm

TeamPCP's CanisterWorm started with a single compromised tool โ€” Trivy โ€” and used stolen tokens to self-replicate across 46+ npm packages. The C2 runs on a blockchain nobody can take down.

TT
Taco Team
Read
Threat Intel8 min read

GlassWorm: A RAT That Hides in a Chrome Extension and Takes Orders from Solana

GlassWorm delivers a three-stage attack via compromised npm packages โ€” ending with a forced Chrome extension install that keystrokes, screenshots, and drains crypto wallets. Its C2 address lives on the blockchain.

TT
Taco Team
Read
Threat Intel6 min read

VS Code Extension fast-draft Backdoored: RAT, Infostealer, and Document Theft

The fast-draft extension on Open VSX โ€” 26,000 downloads โ€” served four concurrent malicious modules: a remote desktop RAT, a browser credential stealer targeting 25 crypto wallets, a document thief, and a clipboard monitor.

TT
Taco Team
Read