Researchers reported a worm-enabled npm supply-chain attack dubbed CanisterWorm that backdoored at least 29 legitimate packages, including 28 in the @EmilGroup scope and @teale.io/eslint-config. The attackers appear to have used stolen npm publishing tokens or equivalent CI/CD access to replace package contents, republish trojanized updates under the latest tag, and spread the malware across additional packages available to the compromised credentials. Aikido linked the activity to TeamPCP and assessed it as a likely follow-on from the earlier Trivy compromise, while Socket said the operation showed high-confidence signs of a legitimate publisher-space takeover with worm-like propagation.
The infection chain used a Node.js postinstall loader, a Python backdoor, and an Internet Computer Protocol canister as a dead-drop command-and-control channel for dynamic payload delivery. On Linux, the malware established persistence through a user-level systemd service, disguised files as PostgreSQL-related artifacts, delayed execution to evade sandboxing, and used a propagation script to enumerate publishable packages, bump patch versions, preserve READMEs, and publish malicious updates at scale. At the time of reporting, the ICP canister returned a Rickroll URL as a dormant kill switch, but researchers warned it could be changed at any time to deliver a real second-stage binary to developers, CI runners, and build systems that installed the compromised packages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-22, Expel reported a separate software supply-chain incident involving the xinference AI model serving framework. The malicious code was described as harvesting AWS, Azure, and Google Cloud credentials, along with SSH keys and Kubernetes secrets, expanding the story beyond the previously documented npm-focused Namastex/CanisterWorm activity.
On 2026-04-22, Socket reported a developing supply-chain incident affecting Namastex Labs-related npm packages, primarily @automagik/genie and pgserve, with install-time malware that steals credentials and wallet data, exfiltrates data, and attempts to self-propagate to npm and PyPI. The report also linked shared malware/key material to malicious packages in the @fairwords and @openwebconcept namespaces, indicating expansion into additional publisher spaces with tradecraft overlapping CanisterWorm/TeamPCP-style activity.
Socket said the Namastex-linked CanisterSprawl activity had affected 22 packages starting on 2026-04-08. The wave was assessed as part of the broader CanisterWorm campaign and involved self-propagating malware targeting npm and, where possible, PyPI.
StepSecurity reported that attackers used harvested npm tokens from compromised CI/CD environments to publish backdoored patch versions across additional npm namespaces, including more than 16 packages in the @opengov scope. This represents a newly disclosed victim set beyond the previously reported @EmilGroup and @teale.io/eslint-config packages.
On 2026-03-22, JFrog reported newly identified compromised npm package versions tied to CanisterWorm, expanding the known list of affected packages beyond earlier public disclosures. The report reiterated TeamPCP attribution and detailed token theft from npm credentials and CI/CD environments used to republish malicious updates under compromised maintainer accounts.
Aikido researcher Charlie Eriksen said the malicious Internet Computer canister associated with CanisterWorm was taken down on Sunday night, ending availability of the malware at that time. The action disrupted the campaign’s dead-drop command channel after its earlier use in the npm supply-chain attack.
Within 48 hours of the initial npm supply-chain activity, researchers reported that CanisterWorm began targeting Kubernetes environments associated with Iran, especially systems in the Asia/Tehran timezone. In these cases, the malware spread via DaemonSet and deployed the destructive Kamikaze wiper, marking a shift from credential theft and backdoor delivery to destructive attacks.
Researchers reported a newer CanisterWorm variant in @teale.io/eslint-config that steals npm tokens during installation and automatically republishes malicious packages using the victim's credentials. This marked an escalation in the campaign by turning infected developers and CI pipelines into new propagation vectors.
At the time of reporting, the malware's ICP canister returned a Rickroll YouTube URL instead of a live second-stage payload, suggesting a dormant or kill-switch state. Researchers warned the actor could change the canister response at any time to deliver a real binary payload.
On 2026-03-20, Aikido and Socket disclosed the CanisterWorm campaign as a worm-enabled npm supply-chain attack affecting legitimate publisher namespaces. Aikido linked the activity to TeamPCP and assessed it as a likely follow-up to the Trivy compromise reported by Wiz less than 24 hours earlier, while Socket described the same campaign without firm attribution.
The trojanized packages used a Node.js postinstall stage to install a persistent Python implant on Linux via a user-level systemd service, disguising artifacts as PostgreSQL-related files. The malware then polled an Internet Computer Protocol canister as a dead-drop command-and-control channel for second-stage payload URLs.
Using stolen publisher access, the attackers pushed malicious versions of 28 packages in the @EmilGroup scope and @teale.io/eslint-config, publishing them under the latest tag to maximize installation. The campaign used a worm-like propagation tool to enumerate additional publishable packages, bump versions, preserve READMEs, and spread through accessible accounts.
Threat actors appear to have obtained npm publishing tokens or equivalent CI/CD publishing access for legitimate publisher namespaces, including the @EmilGroup scope and likely @teale.io/eslint-config. This access enabled them to replace legitimate package contents and publish trojanized updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceexpel.com
Open sourcecybersecuritynews.com
Open sourcecyberpress.org
Open sourcemend.io
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceaikido.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.