Self-propagating malware poisons open source software and wipes Iran-based machines

2026-03-25T08:51:58Zef9714c73e28f66b11e4186734320f47862d122b238ab1f62396fe10119695c3
airsnitchasusbios-accesscastleloadercisadarksworddydxinvisible-unicodeip-kvmiphone-exploitiranknown-exploited-vulnslumma-stealermalicious-packagespassword-manager-compromisepatchingrouter-malwaresecure-bootself-propagating-malwaresupply-chaintrivywifi-bypasswiper-attack

What happened

A series of high-impact security incidents reported by Ars Technica in early 2026 highlight an active, multi-pronged threat landscape: ongoing supply-chain compromises (including a widely used Trivy scanner compromise, invisible/unicode code insertion on GitHub, and malicious packages targeting dYdX) and a self‑propagating malware campaign that poisoned open‑source software and wiped Iran‑based machines. Other major items include a powerful iPhone exploit/tool called “DarkSword” seen in the wild, disclosed vulnerabilities in IP‑KVMs (BIOS‑level access), ~14,000 routers (many Asus) infected by难

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
ef9714c73e28f66b11e4186734320f47862d122b238ab1f62396fe10119695c3
Enrichment time
2026-03-25T08:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Self-propagating malware poisons open source software and wipes Iran-based machines · Baitaphish