Novel supplychain.local Go worm appears
Summary
On 23 September 2026, a threat actor published a novel supply chain worm to the following packages:
- Published
- Collected
Related coverage
blog ·
aikido.dev
Send GitLab an email, push to main
GitLab projects have a button labeled "Email work item to this project".
blog ·
aikido.dev
Graphalgo campaign spreads to Terraform providers and Go Modules
Go malware has appeared in two Terraform providers and two Go modules — the first observed abuse of Terraform providers. The Graphalgo Go port hides a hash-gated trigger with blockchain and Slack C2.
blog ·
aikido.dev
Shai-Hulud Rises From the Dead after 111 days
The Shai-Hulud npm worm payload behind May's @AntV attack resurfaced after 111 days: four new packages on September 7 carried the identical hash, despite npm's new publish-time malware scanning.
blog ·
wiz.io
Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware
Wiz details the Shai-Hulud npm worm — malicious releases harvested secrets with TruffleHog, dumped them to public GitHub repos and self-propagated via stolen npm tokens across 100+ packages.
blog ·
aikido.dev
Aikido and Deel: set up once, secure every hire
Deel's whole job is making it possible to hire flexibly: whether the people are remote, contractors, or spread across entities and countries you don't personally manage. That flexibility is exactly what makes security hard to keep consistent. Access often outlives the project it was granted for. A package, browser extension or AI skill gets installed on a whim. A new dependency reaches a repo before anyone's reviewed it.
blog ·
aikido.dev
Introducing Aikido Altar: the model that makes sovereign security intelligence possible
Altar is Aikido's open-weight security model, derived from GLM-5.3 via quantization and expert pruning (1.51 TB to 328 GB), running on-prem in Aikido Machine, including air-gapped networks.
Skip to content