logo

Compromised Namastex npm Packages Deliver TeamPCP-Style CanisterWorm Malware

ID: c3118da8-c72a-56ec-80e5-30bc9cdbb170

STIX ID: report--c3118da8-c72a-56ec-80e5-30bc9cdbb170

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Tushar Subhra Dutta

...
...

**Supply-chain CanisterWorm campaign in npm:** Malicious updates to Namastex.ai npm packages delivered a self-propagating backdoor (CanisterWorm) that steals npm tokens, cloud credentials, SSH keys, browser wallets and other sensitive data, then exfiltrates it via an ICP canister; the campaign (attributed to TeamPCP) republished infected packages across namespaces by using stolen publish tokens and has produced over 135 malicious artifacts across 64+ packages, requiring immediate token rotation, package audit, and CI/CD credential review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.