Connect with us
DAPA Banner

Tech

5 Gadgets Sold At Costco That Many Gamers Would Consider A Must-Have

Published

on





For people with Costco memberships, you’re spoiled for choice when it comes to discounted tech. These days, there are many electronics you can buy from Costco, like laptops and portable storage options. Not to mention, the retailer is popular for its bundles, wherein you slash the price for products that you would have typically have needed to buy separately. For gamers, Costco can also be a great place to stack up on gadgets that can be used to improve your set-up in meaningful ways.

To start with, Costco is known to sell discounted displays with strong return policies. Although there are some things you should know before buying a TV, Costco offers a ton of options that you can hook up to your console of choice. Afterward, you can proceed to improve elements to your gaming room, like Wi-Fi connectivity or quality cables, that everyone in your household can benefit from. Then, you can invest in ways to make it more immersive, wherein the best options depend on what kind of games you play. For example, you can explore improvements in terms of controllers, introducing more physical feedback, or even just improved audio. With so many gadgets on Costco that can help you take your gaming to the next level, it can be a little overwhelming. But, if you’re curious, here are some options that you can consider adding to cart.

Advertisement

TP-Link Deco X60 Wi-Fi 6 AX3000 Whole-Home Mesh Wi-Fi System

For online gamers, stable internet speed can make or break your next match. In many cases, this is why people tend to opt for LAN cables, which provide stable, wired connections to your router. However, if you’re a handheld console gamer or simply don’t want the hassle of attaching your device to cables, you may have no choice but to stick to Wi-Fi. Unfortunately, this does introduce some problems, especially when it comes to signal issues. And if you live in a home with multiple people or smart devices wherein many devices are connected to the same network, it can also impact the connection. But if you’re looking for a possible work around, you can get high and consistent speeds across multiple devices if you invest in mesh Wi-Fi systems, like the TP-Link Deco X60.

Advertisement

Priced at $139.99, the online exclusive mesh Wi-Fi system that you can get on Costco comes in a pack of three. Capable of hitting up to 3 Gbps with Wi-Fi 6, the three routers can collectively cover up to 7,000 square feet. Apart from letting you connect up to 150 devices, it has added features for parental control. On Costco, this 3-pack TP-Link set has been rated 4.4 stars on average by 3,300+ members. Apart from buying a fancy mesh Wi-Fi system, it’s also good to make sure your routers are located in the right places and the antennas are facing the right way.

Advertisement

SANUS 3 Meter 8K Ultra High-Speed HDMI 2.1 Cables

Designed for 8K viewing at 60 Hz or 4K at 120 Hz, the SANUS Ultra High Speed HDMI can be the perfect companion for all sorts of game nights. A pair of these 9.8 ft SANUS HDMI cables retail for just under $30 on Costco, which is roughly about $15 per unit. Apart from using them on your gaming consoles or computer, these HDMI cables can also be used to view all sorts of content from streaming platforms too. After all, it was made to be able to show Dynamic HDR, which gets you some great visual contrast.

For people who own fancy soundbars, SANUS claims that it can support high-bitrate Enhanced Audio Return Channel (eARC) audio formats and enhanced audio for DTS-HD Master Audio, Dolby Atmos, and so on. With Variable Refresh Rate (VRR), you can expect less display lag during your matches. For reduced interference, SANUS mentions a low EMI design, plus a maximum data transfer speed of up to 48 Gbps. For added durability, each cable is composed of protective features, such as the cotton braided jacket and sure grip connector. Apart from some added flexibility, you can expect less risks in terms of cuts and other damages. A Costco online exclusive, more than 620 customers have rated it about 4.7 stars on average.

Advertisement

Woojer High-Fidelity Haptic Vest 4

For a more immersive experience, the Woojer High-Fidelity Haptic Vest 4 lets you add another layer to your games. Capable of simulating frequencies up to 250 Hz, you can experience the same games differently with the added physical sensations. To help manage its functions and follow up with its software updates, you’ll need to download its integrated app. But if the sensations are starting to feel a little overstimulating, you also have the option to adjust the intensity. Apart from this, you can use it to view latency and battery life. On a full battery, you can expect up to 8 hours of playtime.

When you buy it at Costco, the Woojer Vest 4 retails for $299.99. But take note, it doesn’t include the chance to get free lining, like you would if you bought directly from Woojer website. Out of the box, it does include the vest unit, USB-C cable, 3.5mm audio cable, fast charger, and user manual. Depending on your preference, it can support both wired and Bluetooth headphones. Although it doesn’t have a ton of reviews yet, the early feedback from Costco customers have been promising. As of March 2026, 20 people have rated it an average of 4.7 stars, so you’re likely in good hands. But take note, Woojer did state that while it can fit sizes S to 3XL, it’s not recommended for children under 13.

Advertisement

Xbox Wireless Headset

Although some people can enjoy gaming with their elaborate home theater system, others may need to stay on the quieter side, especially if you live with small children or areas with strict noise compliance rules. For this reason, an Xbox Wireless Headset may be a must-have for you. Unlike other Bluetooth-enabled headsets, this headset has a slew of other features that make it more suitable for gaming.

Compatible with the Xbox One, Xbox Series S & X, and PC, it’s definitely designed to work seamlessly with your Xbox gaming consoles through wireless pairing, so you don’t have to worry about dongles or cables. Not to mention, you can use the Xbox Accessories app to help take it to the next level. For improved in-game chat experience, Microsoft shares useful features like auto-mute and voice isolation. With a 15-hour battery life, you can last a whole day of gaming without having to charge it.

Advertisement

For Costco members, you can snag the Xbox Wireless Headset for $94.99 on its website. As of March 2026, more than 190 people have rated it about 4.6 stars. But take note, some features may require additional Xbox subscription before you can enjoy them. It’s only available in black, so you can’t really expect a lot of cute color options. When you’re not gaming, you can also expect it to work like regular Bluetooth headphones, so you can listen to music and take calls.

Advertisement

Logitech G Driving Force Racing Simulator Bundle

Compatible with the Playstation 4, Playstation 5, and PC, the Logitech G Driving Force Racing Simulator Bundle is a great addition to your gaming arsenal if racing is your thing. In the set, it includes a steering wheel, pedals, and shifter, plus a power supply and user documentation. Logitech mentions that the steering wheel can turn up to 900 degrees lock-to-lock. It also has features like a hall-effect steering sensor, an overheat safeguard, and TRUEFORCE technology, which helps make your racing simulation games feel even more real. And if you want further customization, it has a 24-point selection dial too. Apart from this, it ships with a pedal that is both self-calibrating, has a carpet grip system, and a nonlinear brake pedal. Lastly, the shifter lets you choose between six speeds and works with multiple racing wheels (G923, G29 and G920). Depending on your preference, Logitech mentions that it can be mounted on your racing rig or a table with its built-in clamps.

An Costco online exclusive, this Logitech bundle doesn’t have that many reviews yet. However, early reviews have been largely positive with an average rating of 4.4 stars from 18 people. In tandem with VR headsets, users have praised how it takes realism to another level. Although there were some concerns regarding pedal stabilization, citing the tendency to slide. While the standard retail price is $399.99, Costco has listed it at $100 off or $299.99 for a select period.

Advertisement



Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

‘We should regard it as a privilege to be stepping stones to higher things’: How Arthur C Clarke predicted the rise of AGI and the looming demise of humanity back in 1964

Published

on

While debate over the timeline – or even the potential – for artificial general intelligence (AGI) rages on in 2026, one futurist may have predicted the breakthrough more than 60 years ago.

Noted British science fiction writer and futurist Arthur C. Clarke touted the arrival of AGI during an interview at the 1964 World’s Fair in New York City.

Source link

Continue Reading

Tech

This monitor claims paper-like viewing and huge energy savings by using ambient light instead of relying entirely on traditional backlighting

Published

on


  • Hannspree Hybri monitor uses ambient light to significantly reduce energy consumption
  • Reflective display design aims to mimic paper-like readability and comfort
  • Automatic switching enables backlight use in low ambient light conditions

The Hannspree Hybri monitor attempts to merge paper-like readability with modern display performance, claiming an 80% reduction in energy use through innovative use of ambient light.

At illumination levels above 1000lux, common in offices, classrooms, and outdoor-adjacent spaces, the monitor reflects surrounding light instead of relying solely on a backlight.

Source link

Advertisement
Continue Reading

Tech

Reddit wants to check if you’re using the iPhone’s Face ID camera

Published

on

Reddit may soon ask users to prove they’re human, and it might involve your face. During a TBPN podcast, Reddit’s CEO, Steve Huffman, confirmed that the platform is exploring new identity verification methods, including using Face ID or Touch ID-style authentication, to tackle its growing bot problem.

RDDT requiring Face ID was not something I had on my bingo card but something has got to be done about all the fake / botted content — I just don’t know how to sell face-scanning to redditors or even lurkers. https://t.co/7e7K3Di4ip

— Alexis Ohanian 🗽 (@alexisohanian) March 21, 2026

The idea is simple: as AI-generated accounts become more convincing, Reddit wants stronger ways to confirm that users are real people and not bots pretending to be one.

Why is Reddit considering Face ID-style verification?

Unfortunately, bots are getting too good. Huffman has previously emphasized keeping the platform “human,” and this move fits right into that strategy. AI-generated content and automated accounts are becoming harder to detect, making moderation more challenging and threatening the authenticity of discussions.

Advertisement

As such, verification methods like Face ID or biometric checks could act as a quick way to confirm a real person is behind an account, without requiring traditional ID uploads. But of course, it’s not that simple.

So… are we really scanning faces now?

Reddit isn’t going full sci-fi just yet. The company is still “weighing” its options, which could mean optional verification for certain features, regions, or accounts rather than forcing everyone to scan their face. We’ve already seen a preview of this in places like the UK, where Reddit uses selfies or ID checks for age verification.

The next step could make things feel a lot more seamless and a bit more invasive. Instead of uploading IDs, Reddit may lean on device-level tools like Face ID to confirm you’re human, turning verification into something that happens in the background rather than a full process. Of course, that’s where things get messy.

Biometric checks raise big questions around privacy, data security, and consent, and users aren’t exactly thrilled about handing over their face to prove they’re not a bot. Reddit may be solving one problem, but it opens up another: how much verification is too much? Especially on a platform where anonymity is kind of the whole point?

Source link

Advertisement
Continue Reading

Tech

Google isn't backing away from Pentagon AI work, it's doubling down

Published

on


According to Business Insider, the issue came up during a January Google DeepMind town hall, where VP of Global Affairs Tom Lue said the company was “leaning more” into national security work.
Read Entire Article
Source link

Continue Reading

Tech

Scientists find all five genetic building blocks for life in asteroid Ryugu

Published

on


Researchers are still studying samples of Ryugu collected by the Japanese Aerospace Exploration Agency from its Hayabusa2 mission. After the first papers focused on the composition of the recovered material, a Japanese team has now found a “complete” set of genetic bases belonging to both DNA and RNA.
Read Entire Article
Source link

Continue Reading

Tech

8Today’s NYT Strands Hints, Answer and Help for March 22 #749

Published

on

Looking for the most recent Strands answer? Click here for our daily Strands hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle, Connections and Connections: Sports Edition puzzles.


Today’s NYT Strands puzzle is an intriguing one. It helps if you know a little bit about famous products throughout history. Some of the answers are difficult to unscramble, so if you need hints and answers, read on.

I go into depth about the rules for Strands in this story

Advertisement

If you’re looking for today’s Wordle, Connections and Mini Crossword answers, you can visit CNET’s NYT puzzle hints page.

Read more: NYT Connections Turns 1: These Are the 5 Toughest Puzzles So Far

Hint for today’s Strands puzzle

Today’s Strands theme is: Trademarked no more

Advertisement

If that doesn’t help you, here’s a clue: Brand names that became generic terms.

Clue words to unlock in-game hints

Your goal is to find hidden words that fit the puzzle’s theme. If you’re stuck, find any words you can. Every time you find three words of four letters or more, Strands will reveal one of the theme words. These are the words I used to get those hints but any words of four or more letters that you find will work:

  • SPIT, SPITE, SPITES, SPITS, PIER, PIERS, GAME, SAME, POPE, POPES, GASP

Answers for today’s Strands puzzle

These are the answers that tie into the theme. The goal of the puzzle is to find them all, including the spangram, a theme word that reaches from one side of the puzzle to the other. When you have all of them (I originally thought there were always eight but learned that the number can vary), every letter on the board will be used. Here are the nonspangram answers:

  • ZIPPER, ASPIRIN, THERMOS, DUMPSTER, ESCALATOR

Today’s Strands spangram

completed NYT Strands puzzle for March 22, 2026

The completed NYT Strands puzzle for March 22, 2026.

NYT/Screenshot by CNET

Today’s Strands spangram is GENERICTERM. To find it, start with the G that is three letters down on the far-left row, and wind across and then up again.

Advertisement

Source link

Continue Reading

Tech

MacBook Neo review: the new king of budget laptops

Published

on

Don’t call it compromised. The MacBook Neo is an amazing new entry point in Apple’s lineup that easily eclipses the base iPad and will be a revolution in the education market.

An open MacBook Neo viewed from the back on an outdoor table
MacBook Neo review: A18 Pro is more than enough compute

Apple is no stranger to attempting new and interesting budget products like the entry iPhone 17e or base iPad. While it thrives in the premium market, Apple’s best sellers are at the bottom of the lineup, and that bottom just dropped again for the MacBook.
MacBook Neo is yet another move towards a more affordable Mac that echoes previous attempts, like the iBook. Though, even in 2006, the iBook was a closer relation to today’s MacBook Air than to the MacBook Neo.
Continue Reading on AppleInsider | Discuss on our Forums

Source link

Continue Reading

Tech

Broadcom's VMware shake-up triggers EU antitrust complaint by cloud providers

Published

on


CISPE claims Broadcom’s actions have excluded most European cloud infrastructure partners, sharply reduced competition, and forced smaller firms out of the VMware ecosystem altogether.
Read Entire Article
Source link

Continue Reading

Tech

Why the checkout is the most strategic product in your 2026 stack

Published

on

Every product team has a roadmap. Every marketing team has a funnel. But ask most SaaS and ecommerce leaders which single component has the greatest direct impact on their revenue, and you will hear a surprising amount of hesitation. The answer, increasingly, is the one piece of infrastructure that still gets treated as an afterthought: the checkout.

This article contains affiliate links. If you make a purchase through these links, we may earn a commission at no extra cost to you.

For years, the payment layer lived in a kind of operational blind spot. It worked (mostly), money came in (usually), and nobody thought about it until something broke. That era is ending. In 2026, the checkout has quietly become the single highest-leverage point in the entire commerce stack, and the businesses that recognise this first are pulling ahead in ways their competitors cannot easily replicate.

The $260 billion problem hiding in plain sight

Consider a number that should make every product leader uncomfortable: according to research by Baymard Institute, the average online cart abandonment rate sits at roughly 70 per cent. Seven out of every 10 buyers who reach the point of purchase walk away before completing it. Across US and EU ecommerce combined, that represents approximately $260 billion in lost orders that could be recovered through better checkout design and payment flows alone.

Advertisement

The causes are not mysterious. Unexpected costs at checkout, mandatory account creation, slow page loads, missing local payment options, and clunky authentication flows all chip away at completion rates. What is striking is how many of these problems are entirely solvable, not through better marketing or more aggressive retargeting, but through smarter payment infrastructure.

Advertisement

This is the shift that has made the checkout a strategic concern rather than a back-office one. When a 1 per cent improvement in conversion rate can effectively double the return on your acquisition spend, the infrastructure that governs that final step starts to look less like plumbing and more like the most important product decision you will make this year.

Why payments have become a product problem

The broader payments industry has been moving in this direction for some time. Payment orchestration platforms are growing at a compound annual rate of nearly 26 per cent, driven by the recognition that how you process transactions matters as much as what you sell. Smart routing, tokenisation, AI-driven fraud detection, and localised checkout experiences are no longer optional extras. They are the mechanics of competitiveness.

For SaaS businesses and digital commerce operators in particular, the stakes are compounded by recurring revenue. A failed initial transaction is a lost sale. A failed renewal is a lost customer. Research from 2Checkout’s own platform data shows that 10 to 15 per cent of recurring payments fail to process on the first attempt. Left unaddressed, those failures accumulate into significant involuntary churn, the kind that erodes revenue without any dissatisfaction from the customer at all.

The businesses handling this well are not treating payments as a utility. They are treating the entire checkout and billing layer as a product in its own right, one that requires the same attention to user experience, performance metrics, and iterative improvement as any customer-facing feature.

Advertisement

What a modern checkout actually needs to do

If the checkout is now a strategic product, what does a good one look like in 2026? The requirements have expanded considerably beyond simply accepting a credit card number.

First, it needs to be global by default. Selling across borders means supporting local payment methods, local currencies, and local compliance requirements. A customer in the Netherlands expects iDEAL. A buyer in Brazil may want to pay via Boleto Bancário. Showing only Visa and Mastercard to a global audience is, at this point, leaving money on the table.

Second, it needs to handle recurring billing natively. Subscription businesses need more than a payment gateway. They need dunning management, account updater services that automatically refresh expired card details, and intelligent retry logic that resubmits failed transactions at optimal times through the right acquirer. These are not nice-to-have features. They are the difference between a 5 per cent churn rate and a 12 per cent one.

Third, it needs to manage compliance. Global tax obligations, fraud screening, PCI DSS compliance, and 3D Secure authentication all need to be handled cleanly, without creating friction for the buyer or operational overhead for the seller. For many growing businesses, managing tax registrations and filings across dozens of jurisdictions is a full-time job in itself.

Advertisement

Finally, it needs to be measurable. Authorisation rates, conversion rates by geography, decline reasons, and recovery rates are the metrics that separate a well-run payment operation from a neglected one. If you cannot see where transactions are failing, you cannot fix what is costing you revenue.

How 2Checkout approaches the problem

2Checkout (now part of Verifone) has built its platform around the idea that payments, billing, and compliance should be one integrated system rather than a collection of bolted-on services. The platform supports sales in over 200 countries and territories, accepts 45+ payment methods in 100+ currencies, and offers three tiers designed to match different stages of business complexity.

At the entry level, 2Sell handles straightforward online and mobile payment processing with smart routing to optimise authorisation rates. 2Subscribe adds full subscription lifecycle management: recurring billing, dunning, account updater, retry logic, renewal handling, and churn analytics, all bundled into the per-transaction fee. At the top tier, 2Monetize acts as a full merchant of record, meaning 2Checkout legally becomes the seller, handles global VAT and sales tax calculation, collection, and remittance, manages fraud liability, and takes on regulatory compliance across every market.

That merchant of record model is worth pausing on. For a SaaS company selling in 30 or more countries, the alternative is managing dozens of individual tax registrations and ongoing filings, or layering on separate tax calculation services that still leave you responsible for remittance. Having a platform that absorbs that entire burden changes the operational equation significantly.

Advertisement

The revenue recovery capabilities are equally worth noting. 2Checkout’s Account Updater has helped vendors salvage over 90 per cent of otherwise unusable cards used for recurring billing. Combined with smart retry logic and dunning management, clients on the platform have reported revenue uplifts of up to 23 per cent and recovery rates of 35 per cent on auto-recurring transactions. In subscription businesses, where each recovered payment represents months or years of future customer lifetime value, those numbers translate directly to the bottom line.

The real cost of getting payments wrong

The financial argument for treating payments strategically is not subtle. Smart routing alone, which directs transactions to local processors where authorisation rates are highest, has enabled vendors on 2Checkout’s platform to see up to 40 per cent increases in authorisation rates in markets like Brazil, Turkey, and the US. Each percentage point of authorisation improvement maps to real revenue that would otherwise vanish as a declined transaction.

But the costs of a poor payment setup extend beyond lost transactions. Every failed renewal that leads to involuntary churn carries the cost of customer acquisition that went to waste. Every checkout that sends a customer away because it did not support their preferred payment method is a marketing dollar that generated interest but not revenue. Every hour spent manually reconciling tax filings across jurisdictions is time not spent on product or growth.

The compounding nature of these losses is what makes the checkout so strategic. Small improvements in authorisation rates, conversion rates, and retention rates do not just add up. They multiply, because each recovered customer generates future revenue across their entire lifecycle.

Advertisement

What this means for your 2026 planning

If your payment infrastructure has not been reviewed in the past 12 months, it is likely leaving money on the table. The question is not whether you need a modern checkout, but what specifically is costing you revenue in the one you have.

Start by looking at your authorisation rates by geography. If certain markets show significantly lower success rates, your routing may not be optimised for local acquiring. Check your involuntary churn. If failed payments are a meaningful contributor, you likely need better retry logic and account updater services. Audit your compliance overhead. If you are spending significant time or money managing tax obligations across multiple countries, a merchant of record model may simplify your operations and reduce risk.

2Checkout offers a free starting point for businesses that want to explore what an integrated approach looks like, with no monthly fees and charges only on successful transactions. For startups and growing businesses testing international waters, the barrier to entry is essentially zero: sign up for free, start selling, and pay only when you earn.

The companies that will outperform in the coming year are not necessarily the ones with the best product or the biggest marketing budget. They are the ones that recognised early that the checkout is not the end of the funnel. It is the beginning of the customer relationship, and it deserves the same strategic attention as everything that comes before it.

Advertisement

Source link

Continue Reading

Tech

Trivy vulnerability scanner breach pushed infostealer via GitHub Actions

Published

on

Trivy

The Trivy vulnerability scanner was compromised in a supply-chain attack by threat actors known as TeamPCP, which distributed credential-stealing malware through official releases and GitHub Actions.

Trivy is a popular security scanner that helps identify vulnerabilities, misconfigurations, and exposed secrets across containers, Kubernetes environments, code repositories, and cloud infrastructure. Because developers and security teams commonly use it, it is a high-value target for attackers to steal sensitive authentication secrets.

The breach was first disclosed by security researcher Paul McCarty, who warned that Trivy version 0.69.4 had been backdoored, with malicious container images and GitHub releases published to users.

Further analysis by Socket and later by Wiz determined that the attack affected multiple GitHub Actions, compromising nearly all version tags of the trivy-action repository.

Advertisement

Researchers found that threat actors compromised Trivy’s GitHub build process, swapping the entrypoint.sh in GitHub Actions with a malicious version and publishing trojanized binaries in the Trivy v0.69.4 release, both of which acted as infostealers across the main scanner and related GitHub Actions, including trivy-action and setup-trivy.

The attackers abused a compromised credential with write access to the repository, allowing them to publish malicious releases. These compromised credentials are from an earlier March breach, in which credentials were exfiltrated from Trivy’s environment and not fully contained.

The threat actor force-pushed 75 out of 76 tags in the aquasecurity/trivy-action repository, redirecting them to malicious commits.

As a result, any external workflows using the affected tags automatically executed the malicious code before running legitimate Trivy scans, making the compromise difficult to detect.

Advertisement

Socket reports that the infostealer collected reconnaissance data and scanned systems for a wide range of files and locations known to store credentials and authentication secrets, including:

  • Reconnaissance data: hostname, whoami, uname, network configuration, and environment variables
  • SSH: private and public keys and related configuration files
  • Cloud and infrastructure configs: Git, AWS, GCP, Azure, Kubernetes, and Docker credentials
  • Environment files: .env and related variants
  • Database credentials: configuration files for PostgreSQL, MySQL/MariaDB, MongoDB, and Redis
  • Credential files: including package manager and Vault-related authentication tokens
  • CI/CD configurations: Terraform, Jenkins, GitLab CI, and similar files
  • TLS private keys
  • VPN configurations
  • Webhooks: Slack and Discord tokens
  • Shell history files
  • System files: /etc/passwd, /etc/shadow, and authentication logs
  • Cryptocurrency wallets
Infostealer harvesting credentials, SSH keys, and environment files
Infostealer harvesting credentials, SSH keys, and environment files
Source: BleepingComputer

The malicious script would also scan memory regions used by the GitHub Actions Runner.Worker process for the JSON string “" ":{ "value": "", "isSecret":true}” to find additional authentication secrets.

On developer machines, the trojanized Trivy binary performed similar data collection, gathering environment variables, scanning local files for credentials, and enumerating network interfaces.

Collected data was encrypted and stored in an archive named tpcp.tar.gz, which was then exfiltrated to a typosquatted command-and-control server at scan.aquasecurtiy[.]org.

If exfiltration failed, the malware created a public repository named tpcp-docs within the victim’s GitHub account and uploaded the stolen data there.

Advertisement

To persist on a compromised device, the malware would also drop a Python payload at ~/.config/systemd/user/sysmon.py and register it as a systemd service. This payload would check a remote server for additional payloads to drop, giving the threat actor persistent access to the device.

The attack is believed to be linked to a threat actor known as TeamPCP, as one of the infostealer payloads used in the attack has a “TeamPCP Cloud stealer” comment as the last line of the Python script.

“The malware self-identifies as TeamPCP Cloud stealer in a Python comment on the final line of the embedded filesystem credential harvester. TeamPCP, also tracked as DeadCatx3, PCPcat, and ShellForce, is a documented cloud-native threat actor known for exploiting misconfigured Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers,” explains Socket.

Comment showing the script was named TeamPCP Cloud Stealer
Comment showing the script was named TeamPCP Cloud Stealer
Source: BleepingComputer

Aqua Security confirmed the incident, stating that a threat actor used compromised credentials from the earlier incident that was not properly contained.

“This was a follow up from the recent incident (2026-03-01) which exfiltrated credentials. Our containment of the first incident was incomplete,” explained Aqua Security.

Advertisement

“We rotated secrets and tokens, but the process wasn’t atomic and attackers may have been privy to refreshed tokens.”

The malicious Trivy release (v0.69.4) was live for approximately three hours, with compromised GitHub Actions tags remaining active for up to 12 hours.

The attackers also tampered with the project’s repository, deleting Aqua Security’s initial disclosure of the earlier March incident.

Organizations that used affected versions during the incident should treat their environments as fully compromised.

Advertisement

This includes rotating all secrets, such as cloud credentials, SSH keys, API tokens, and database passwords, and analyzing systems for additional compromise.

Follow-up attack spreads CanisterWorm via npm

Researchers at Aikido have also linked the same threat actor to a follow-up campaign involving a new self-propagating worm named “CanisterWorm,” which targets npm packages.

The worm compromises packages, installs a persistent backdoor via a systemd user service, and then uses stolen npm tokens to publish malicious updates to other packages.

“Self-propagating worm. deploy.js takes npm tokens, resolves usernames, enumerates all publishable packages, bumps patch versions, and publishes the payload across the entire scope. 28 packages in under 60 seconds,” highlights Aikido.

Advertisement

The malware uses a decentralized command-and-control mechanism using Internet Computer (ICP) canisters, which act as a dead-drop resolver that provides URLs for additional payloads. 

Using ICP canisters makes the operation more resistant to takedown, as only the canister’s controller can remove it, and any attempt to stop it would require a governance proposal and network vote.

The worm also includes functionality to harvest npm authentication tokens from configuration files and environment variables, enabling it to spread across developer environments and CI/CD pipelines.

At the time of analysis, some of the secondary payload infrastructure was inactive or configured with harmless content, but the researchers say this could change at any time.

Advertisement

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

Source link

Continue Reading

Trending

Copyright © 2025