logo

Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths

ID: c4547b68-a2a2-56a4-9da9-c827e923450c

STIX ID: report--c4547b68-a2a2-56a4-9da9-c827e923450c

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Sonatype Security Research Team

...
...

Sonatype details CanisterSprawl, a self-propagating npm malware campaign that steals sensitive developer data (tokens, API keys) and seeks to abuse compromised publisher accounts to publish additional malicious packages, creating an elevated software supply-chain threat. Organizations are urged to remove infected packages, rotate exposed secrets, and monitor for unauthorized publishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.