CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages
Blog post from Socket
Socket's Threat Research Team discovered a worm-enabled npm supply chain attack, dubbed CanisterWorm, targeting legitimate publisher namespaces, including @emilgroup and @teale.io/eslint-config. The attack involved compromising npm publishing tokens to insert malicious code into packages, which were then redistributed, retaining trust cues like original package names and READMEs. The malware employed a Python backdoor that used an Internet Computer Protocol (ICP) canister as a command-and-control channel, enabling the attacker to change payloads without altering the existing implant on infected systems. The attack progressed through phases, initially serving as a staging framework before embedding a hardcoded Python dropper and refining the worm to boost the likelihood of installation. Targeted victims included developers and systems using Linux hosts, where compromised npm packages persisted through systemd. The incident was a legitimate publisher compromise rather than a typosquat, with evidence pointing to a broad compromise involving the same malware family and propagation chain. Despite the detailed analysis of malware mechanics and propagation, the threat actor's identity remains unattributed, and the investigation is ongoing.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.