Recent investigations by cybersecurity experts have uncovered a new threat involving compromised npm packages that facilitate the spread of a self-replicating worm. This malicious software exploits stolen developer tokens to propagate itself further within the software supply chain. Security firms Socket and StepSecurity have been monitoring this activity, which they have dubbed CanisterSprawl. The name stems from the worm's use of an ICP canister to extract sensitive information from affected systems. Developers are urged to remain vigilant and take necessary precautions to protect their tokens and code repositories from such attacks.
Self-Replicating Supply Chain Worm Compromises npm Packages to Exfiltrate Developer Tokens
A new supply chain worm has been identified, targeting npm packages to steal developer tokens through a self-replicating mechanism.
