CanisterWorm Hijacks npm Publisher Accounts, Steals Tokens
ID: 0c496fa9-cfc8-5f0b-a952-95f577a2f168
STIX ID: report--0c496fa9-cfc8-5f0b-a952-95f577a2f168
Feed Name: GBHackers
A highly automated npm supply-chain campaign named "CanisterWorm" abuses stolen npm publishing tokens and CI/CD access to backdoor legitimate, already-trusted packages by injecting malicious postinstall hooks that install a Python backdoor which persists via a user-level systemd service (pgmon). The backdoor uses an ICP canister as a dead-drop C2 to fetch payloads, harvests npm tokens from config files and environment variables, and automatically republish-backdoors all packages a compromised account can publish, creating rapid, ecosystem-wide propagation; the report includes indicators (service name, paths, ICP endpoint, compromised package versions) and mitigation guidance such as rotating tokens, removing persistence, and disabling lifecycle scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
