Get Started

Supply Chain Attack Campaign

Ongoing

CanisterWorm

CanisterWorm is a worm-enabled npm supply chain campaign that compromises legitimate publisher space, replaces package contents with install-time malware, establishes Linux persistence through systemd --user, and uses an ICP canister dead drop to deliver follow-on binaries. The campaign also includes a republishing component that uses compromised npm publishing access to spread the malicious payload across additional packages while preserving legitimate READMEs as camouflage.

Ecosystems: npm

First discovered
2026-03-20
Last activity
2026-03-23
Affected Package Artifacts
141
(66 unique packages)
Package Artifacts Last 7 Days
0
0%
vs previous 7 days

Blog Coverage

Affected packages

Package
Published
Detected
Download CSV

Socket for GitHub

Socket Firewall

Socket CLI

Socket Certified Patches

Socket Web Extension

Socket Optimize

Socket Dependency Search

Socket Reachability

Languages

JavaScript / TypeScript

Stay in touch

Get open source security insights delivered straight into your inbox.

Book a DemoGet Started

Made with ⚡️ by Socket Inc

U.S. Patent No. 12,346,443 & 12,314,394. Other pending.

SOC 2 Type II certified