logo

Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens

ID: e2c1e292-c865-5e6f-8e20-f85cecb114d1

STIX ID: report--e2c1e292-c865-5e6f-8e20-f85cecb114d1

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Security researchers identified a self-propagating supply-chain worm dubbed "CanisterSprawl" that compromises developer environments via malicious postinstall hooks in npm packages to harvest credentials (npm tokens, cloud keys, SSH keys, browser wallets, container/Kubernetes/Terraform secrets, shell histories, etc.), exfiltrates data to an HTTPS webhook and an ICP canister, and leverages stolen tokens to publish further poisoned npm (and PyPI) packages; the report also details related package compromises (including xinference) and CI/PR-based campaigns (prt-scan) that abuse pull_request_target to steal secrets and publish malicious packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.