Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
ID: e2c1e292-c865-5e6f-8e20-f85cecb114d1
STIX ID: report--e2c1e292-c865-5e6f-8e20-f85cecb114d1
Feed Name: The Hacker News
Security researchers identified a self-propagating supply-chain worm dubbed "CanisterSprawl" that compromises developer environments via malicious postinstall hooks in npm packages to harvest credentials (npm tokens, cloud keys, SSH keys, browser wallets, container/Kubernetes/Terraform secrets, shell histories, etc.), exfiltrates data to an HTTPS webhook and an ICP canister, and leverages stolen tokens to publish further poisoned npm (and PyPI) packages; the report also details related package compromises (including xinference) and CI/PR-based campaigns (prt-scan) that abuse pull_request_target to steal secrets and publish malicious packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
