Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Coinbase intoduces AI advisor, stock options, and pre-IPO markets in finance push

June 16, 2026

WIF Price Prediction: Smart Money Is Buying the Bounce — But the Bear Structure Hasn’t Broken

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Npm Supply Chain Attack Uses Worm-Like Propagation
Npm Supply Chain Attack Uses Worm-Like Propagation
Security

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026No Comments2 Mins Read

Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across developer ecosystems.

According to new research from Socket, the activity mirrors earlier worm-style supply chain attacks that used blockchain-hosted infrastructure, including Internet Computer Protocol (ICP) canisters, for command and control (C2).

Impacted packages include multiple versions of @automagik/genie and pgserve, both linked to developer tooling workflows. Researchers found the malware executes during installation, harvesting sensitive data and attempting to republish compromised packages using stolen credentials.

Malware Focuses on Sensitive Data

The payload scans infected systems for secrets stored in environment variables and configuration files. Targeted data includes cloud credentials, CI/CD tokens, SSH keys and local developer artifacts such as .npmrc and shell histories.

It also attempts to access browser-stored data and cryptocurrency wallets, including Chrome profiles and extensions like MetaMask and Phantom.

Exfiltration occurs through two channels: a standard HTTPS webhook and an ICP endpoint. Data can be encrypted using AES-256 and RSA methods, though plaintext fallback is possible.

Self-Propagation and Possible Repository Compromise

A key feature of the malware  is its ability to spread. The malware extracts npm tokens, identifies accessible packages, injects malicious code, and republishes them, enabling further compromise across the ecosystem.

It also includes functionality to propagate via Python’s PyPI repository by generating malicious packages using .pth file injection when credentials are present.

Read more on similar threats: Malicious Machine Learning Model Attack Discovered on PyPI

Researchers observed similarities with prior TeamPCP-linked campaigns, including the use of post-install scripts and canister-based infrastructure. However, the exact source of the compromise remains under investigation.

See also  Will $7.2B BTC in seized Bitcoin crash the market in January?

Evidence suggests legitimate projects may have been hijacked. Some affected packages have active usage, with one showing over 6,700 weekly downloads. Inconsistencies between npm releases and Git tags further raise suspicion.

Socket said the situation is still evolving, with additional malicious versions continuing to emerge and the full scope of the attack not yet confirmed.

Source link

attack Chain npm Propagation Supply WormLike

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

HBAR Breaks $0.12 Within Two Weeks – Compression Setup Signals 40% Rally

April 21, 2026

NetX Joins GANA to Advance Web3 Payments with PayFi Innovation

March 19, 2026

Ayatollah Mojtaba Khamenei Surrounded By 24/7 Medical Team In Hideout As Generals Run Iran: NYT

April 23, 2026

Type above and press Enter to search. Press Esc to cancel.