Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New CanisterWorm Steals npm Tokens and Spreads Through Compromised Publisher Accounts

A new malware campaign known as CanisterWorm has emerged, targeting the npm ecosystem through supply chain attacks. This self-propagating malware is linked to an entity identified as "TeamPCP" and compromises legitimate publisher namespaces to distribute…

A new malware campaign known as CanisterWorm has emerged, targeting the npm ecosystem through supply chain attacks. This self-propagating malware is linked to an entity identified as "TeamPCP" and compromises legitimate publisher namespaces to distribute malicious package versions.

The malware is concealed within routine SDK version updates, making it challenging for developers to detect. Initial identification of the CanisterWorm attack was made by security researchers from Socket and Endor Labs, who observed malicious package updates across various npm publisher accounts.

Further investigation by JFrog researchers revealed additional compromised package versions, expanding the known scope of the campaign. The malware utilizes a Python backdoor to harvest npm authentication tokens, enabling it to spread autonomously across packages maintained by compromised developers.

The infection occurs when a developer executes npm install on a compromised package. A malicious postinstall script embedded in the package.json file installs a Python backdoor on the host system. On Linux, the worm registers as a persistent background service named pgmon via systemd .

Once active, the backdoor communicates with a decentralized command-and-control server, blending in with regular web traffic and evading detection by conventional network monitoring tools. The worm uses stolen authentication tokens to update and publish tainted packages automatically.

A new malware campaign known as CanisterWorm has emerged, targeting the npm ecosystem through supply chain attacks.
Peter Collins · Thehackingpost

The following table lists some of the known compromised packages and their affected versions:

Package Name Compromised Version(s) JFrog X-ray ID

@pypestream/floating-ui-dom 2.15.1 XRAY-955001

@leafnoise/mirage 2.0.3 XRAY-954938

Advertisement

Developers using compromised package versions must assume their environment is infected. It is crucial to rotate all npm publishing tokens found in .npmrc files, environment variables, and CI/CD pipeline secrets. On Linux systems, the pgmon service should be stopped and removed using systemctl , and temporary files /tmp/pglog and /tmp/.pg_state must be deleted.

Compromised node_modules directories should be rebuilt from verified package versions. Developers with stolen tokens must manually unpublish affected package versions to prevent further distribution. Globally setting npm config set ignore-scripts true can prevent silent execution of postinstall hooks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories