CanisterWorm: Malicious npm Packages Deploy Self-Propagating Supply Chain Worm
Blog post from Endor Labs
A new campaign targeting developers involves numerous malicious npm packages that execute harmful postinstall scripts without user awareness, compromising systems by stealing authentication tokens and establishing backdoors. The malware scans for npm credentials to act as a supply chain worm, injecting itself into legitimate packages and spreading throughout the open-source ecosystem. It also establishes persistent access on Linux systems by creating hidden services and retrieves additional payloads from a decentralized Internet Computer (ICP) blockchain, making it resistant to takedown efforts. The attack's resilience is enhanced by using Base64 encoding to obscure its Python payload and leveraging ICP infrastructure for command and control. To mitigate the threat, developers are advised to inspect dependency files, check for dropped payloads, review network logs for suspicious activity, and audit npm accounts for unauthorized actions. Long-term prevention strategies include disabling automatic script execution, implementing dependency vetting, adopting the principle of least privilege for credentials, and using supply chain security tools.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Vector Search | 1 | 2,370 | 415 | 145 | +7% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.