worm
Safeguard articles tagged "worm" — guides, analysis, and best practices for software supply chain and application security.
7 articles
Conficker (2008): The Worm That Outlived Its Own Patch by a Decade
A factual retrospective on Conficker, which exploited MS08-067 in late 2008, built a botnet of millions of hosts, and remained detectable on hundreds of thousands of machines many years after the patch shipped.
Code Red (2001): The Worm That Made Buffer Overflows Everyone’s Problem
A factual retrospective on the July 2001 Code Red worm, which exploited a buffer overflow in Microsoft IIS, infected hundreds of thousands of servers, and helped establish modern patch management as a discipline.
SQL Slammer (2003): 376 Bytes That Saturated the Internet in Minutes
A factual retrospective on the January 2003 SQL Slammer worm, which exploited a patched buffer overflow in Microsoft SQL Server and doubled in size every 8.5 seconds, disrupting internet infrastructure globally.
Your Dependency Incident Runbook Assumes a Fixed List of Bad Packages
Most supply chain runbooks say: get the affected package list, search lockfiles, remediate. Against a worm that adds packages while you work, every one of those steps is wrong.
Python's .pth Files Are a Code Execution Primitive, and Attackers Noticed
The June 2026 PyPI worm wave used a *-setup.pth file to execute at interpreter startup — before your code, before your imports, on every single python invocation. It then fetched the Bun JavaScript runtime to run its payload. If your supply chain model stops at setup.py, it has a hole in it.
Lessons from Shai-Hulud: The First Self-Propagating npm Worm
In September 2025, npm faced a supply chain attack that spread by itself — stealing developers' tokens, then using them to trojanize the victims' own packages. Here is how it worked.
Shai-Hulud: The Self-Replicating npm Worm That Hit 500+ Packages
On September 15, 2025, a self-replicating npm worm dubbed Shai-Hulud backdoored more than 500 packages, including @ctrl/tinycolor and CrowdStrike libraries, by pivoting through stolen publish tokens.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.