Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,195
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

Last month's discovery of a malicious npm supply chain campaign, linked to TeamPCP supply chain attacks, revealed a worm-enabled malware operation targeting specialized developer workflows through compromised package publisher spaces. The campaign involved packages such as @automagik/genie and pgserve, which were altered to include install-time malware capable of credential theft, data exfiltration via ICP canisters, and self-propagation across ecosystems. The malware's sophisticated design mimics previous canister-backed npm worms, employing techniques like install-time execution, cross-ecosystem propagation, and off-host data exfiltration. The incident, affecting packages related to Namastex Labs and others, remains under investigation, with ongoing identification of malicious versions and scrutiny over release anomalies. The affected packages, deeply integrated into AI and development tools, highlight significant ecosystem vulnerabilities, prompting recommended security measures like blocking compromised versions and rotating credentials.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 4 1,821 338 111 +22%
AI Agents 1 4,430 1,100 236 -3%
AI Coding Assistant 1 1,480 382 153 +18%
Kubernetes 1 2,306 381 103 +25%
LLM 1 5,932 1,046 223 -2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.