Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
ID: ad44b14b-9016-5099-ba54-81e6ef59e9b3
STIX ID: report--ad44b14b-9016-5099-ba54-81e6ef59e9b3
Feed Name: The Hacker News
A newly documented malware campaign dubbed CanisterWorm is propagating through compromised npm packages (multiple scoped packages listed) by using postinstall hooks to install a Python backdoor that contacts an Internet Computer (ICP) canister acting as a decentralized dead-drop C2. The worm collects npm authentication tokens from developer environments and either a manual deploy script or an updated postinstall variant spawns a background deployer to publish malicious versions, enabling broad supply-chain propagation; persistence uses a masqueraded systemd user service and the ICP canister allows the attacker to swap payload URLs at will.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
