BotBeat
...
← Back

> ▌

N/AN/A
INDUSTRY REPORTN/A2026-03-23

CanisterWorm: Supply Chain Attack Compromises 29+ npm Packages Through Publisher Account Takeovers

Key Takeaways

  • ▸A new supply chain worm named CanisterWorm compromised 29+ npm packages by exploiting publisher account vulnerabilities
  • ▸The attack leveraged ICP (Internet Computer Protocol) canisters for command and control infrastructure, representing an novel abuse of blockchain technology
  • ▸Multiple publisher accounts (@emilgroup, @teale.io) were successfully compromised, allowing attackers to inject malicious code across their entire package portfolios
Source:
Hacker Newshttps://socket.dev/blog/trivy-docker-images-compromised↗

Summary

A sophisticated supply chain attack dubbed CanisterWorm has compromised multiple npm package publishers, affecting 29+ packages across the ecosystem. The attack exploited compromised publisher accounts associated with @emilgroup and @teale.io, using an Internet Computer Protocol (ICP) canister as an infrastructure component to deliver follow-on payloads to affected systems. The worm's modular design allowed it to propagate across multiple packages and establish persistent backdoor access, demonstrating the expanding threat landscape for open-source software dependencies. This incident underscores the critical vulnerabilities in the npm supply chain, where a single compromised publisher account can impact dozens of downstream projects and their users.

  • The incident highlights critical gaps in npm ecosystem security and the need for stronger publisher authentication and package integrity verification
CybersecurityMisinformation & DeepfakesOpen Source

More from N/A

N/AN/A
RESEARCH

Machine Learning Model Identifies Thousands of Unrecognized COVID-19 Deaths in the US

2026-04-05
N/AN/A
POLICY & REGULATION

Trump Administration Proposes Deep Cuts to US Science Agencies While Protecting AI and Quantum Research

2026-04-05
N/AN/A
RESEARCH

UCLA Study Reveals 'Body Gap' in AI: Language Models Can Describe Human Experience But Lack Embodied Understanding

2026-04-04

Comments

Suggested

GitHubGitHub
PRODUCT LAUNCH

GitHub Launches Squad: Open Source Multi-Agent AI Framework to Simplify Complex Workflows

2026-04-05
SourceHutSourceHut
INDUSTRY REPORT

SourceHut's Git Service Disrupted by LLM Crawler Botnets

2026-04-05
AnthropicAnthropic
POLICY & REGULATION

Security Researcher Exposes Critical Infrastructure After Following Claude's Configuration Advice Without Authentication

2026-04-05
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us