Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Blog post from Socket
Last month's discovery of a malicious npm supply chain campaign, linked to TeamPCP supply chain attacks, revealed a worm-enabled malware operation targeting specialized developer workflows through compromised package publisher spaces. The campaign involved packages such as @automagik/genie and pgserve, which were altered to include install-time malware capable of credential theft, data exfiltration via ICP canisters, and self-propagation across ecosystems. The malware's sophisticated design mimics previous canister-backed npm worms, employing techniques like install-time execution, cross-ecosystem propagation, and off-host data exfiltration. The incident, affecting packages related to Namastex Labs and others, remains under investigation, with ongoing identification of malicious versions and scrutiny over release anomalies. The affected packages, deeply integrated into AI and development tools, highlight significant ecosystem vulnerabilities, prompting recommended security measures like blocking compromised versions and rotating credentials.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 4 | 1,821 | 338 | 111 | +22% |
| AI Agents | 1 | 4,430 | 1,100 | 236 | -3% |
| AI Coding Assistant | 1 | 1,480 | 382 | 153 | +18% |
| Kubernetes | 1 | 2,306 | 381 | 103 | +25% |
| LLM | 1 | 5,932 | 1,046 | 223 | -2% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.