Home / Companies / Socket / Blog / Post Details
Content Deep Dive

CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,361
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team discovered a worm-enabled npm supply chain attack, dubbed CanisterWorm, targeting legitimate publisher namespaces, including @emilgroup and @teale.io/eslint-config. The attack involved compromising npm publishing tokens to insert malicious code into packages, which were then redistributed, retaining trust cues like original package names and READMEs. The malware employed a Python backdoor that used an Internet Computer Protocol (ICP) canister as a command-and-control channel, enabling the attacker to change payloads without altering the existing implant on infected systems. The attack progressed through phases, initially serving as a staging framework before embedding a hardcoded Python dropper and refining the worm to boost the likelihood of installation. Targeted victims included developers and systems using Linux hosts, where compromised npm packages persisted through systemd. The incident was a legitimate publisher compromise rather than a typosquat, with evidence pointing to a broad compromise involving the same malware family and propagation chain. Despite the detailed analysis of malware mechanics and propagation, the threat actor's identity remains unattributed, and the investigation is ongoing.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.