Worm-Like npm Malware Hijacks Developer Systems
A self-propagating npm supply chain attack spreads CanisterWorm malware through compromised packages, stealing developer credentials and republishing infected versions across ecosystems. The malware extracts SSH keys, cloud credentials, and crypto wallets while exfiltrating data via encrypted channels and Internet Computer canister infrastructure. It further propagates by abusing stolen npm tokens to infect additional packages and extend cross-ecosystem compromise into PyPI.
Source: Socket
Read more: CyberSecBrief









