Skip to main content

Glossary

Worm

Self-replicating malware that spreads automatically across networks and systems by exploiting vulnerabilities, without requiring any user interaction, unlike a virus, which needs a host program or user action to propagate. Because they self-propagate, worms can spread extremely quickly once released.

Recent coverage mentioning Worm

MEDIUM
Supply Chain

TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks

Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.

Runtime Rebel Intel
3 min read · Sep 1, 2026
SDLC Supply Chain Attacks Target Developer Tools & CI/CD
HIGH
Supply Chain

SDLC Supply Chain Attacks Target Developer Tools & CI/CD

Attackers target the software development lifecycle, exploiting developer tools, CI/CD pipelines, and open-source dependencies to inject malware and backdoors.

Runtime Rebel Intel
4 min read · Aug 22, 2026
CRITICAL
Supply Chain

TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs

A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security's Trivy scanner, not LiteLLM.

Runtime Rebel Intel
5 min read · Aug 15, 2026
npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises
HIGH
Supply Chain

npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises

The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.

Runtime Rebel Intel
5 min read · Aug 8, 2026
ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat
MEDIUM
Supply Chain

ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat

Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.

Runtime Rebel Intel
3 min read · Aug 7, 2026
HIGH
Supply Chain

Keyv npm Supply-Chain Attack: Worm Infection and Dead-Man Switch

Analyze the Keyv/cacheable npm supply-chain worm, its AI agent execution vectors, and why immediate credential revocation can trigger payloads.

Runtime Rebel Intel
3 min read · Aug 6, 2026

Advertisement

← All 285 glossary terms