logo

Malicious Namastex npm Packages Spread TeamPCP-Like CanisterWorm Malware

ID: cd488c38-a021-586e-9d4d-8a978418e0bb

STIX ID: report--cd488c38-a021-586e-9d4d-8a978418e0bb

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Varshini

...
...

**Executive summary:** Researchers have identified a supply-chain campaign distributing malicious npm packages (e.g., @automagik/genie, pgserve) that run at install to steal developer secrets, exfiltrate data via HTTPS and Internet Computer canisters, and propagate by abusing publishing access and cross-ecosystem techniques; the activity shows strong links to TeamPCP/CanisterWorm-like behavior and defenders are urged to remove affected versions, rotate exposed secrets, and hunt internal repositories for related IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.