Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Fairshake ramps up election spending as CLARITY faces deadline

June 24, 2026

SecondFI’s $2M exploit: A wallet flaw leaves Cardano users exposed

June 24, 2026

Aztec Reaches L2Beat Stage 2 After Governance Revokes Rollup Contract Ownership

June 24, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Npm Supply Chain Attack Uses Worm-Like Propagation
Npm Supply Chain Attack Uses Worm-Like Propagation
Security and Privacy

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across developer ecosystems.

According to new research from Socket, the activity mirrors earlier worm-style supply chain attacks that used blockchain-hosted infrastructure, including Internet Computer Protocol (ICP) canisters, for command and control (C2).

Impacted packages include multiple versions of @automagik/genie and pgserve, both linked to developer tooling workflows. Researchers found the malware executes during installation, harvesting sensitive data and attempting to republish compromised packages using stolen credentials.

Malware Focuses on Sensitive Data

The payload scans infected systems for secrets stored in environment variables and configuration files. Targeted data includes cloud credentials, CI/CD tokens, SSH keys and local developer artifacts such as .npmrc and shell histories.

It also attempts to access browser-stored data and cryptocurrency wallets, including Chrome profiles and extensions like MetaMask and Phantom.

Exfiltration occurs through two channels: a standard HTTPS webhook and an ICP endpoint. Data can be encrypted using AES-256 and RSA methods, though plaintext fallback is possible.

Self-Propagation and Possible Repository Compromise

A key feature of the malware  is its ability to spread. The malware extracts npm tokens, identifies accessible packages, injects malicious code, and republishes them, enabling further compromise across the ecosystem.

It also includes functionality to propagate via Python’s PyPI repository by generating malicious packages using .pth file injection when credentials are present.

Read more on similar threats: Malicious Machine Learning Model Attack Discovered on PyPI

Researchers observed similarities with prior TeamPCP-linked campaigns, including the use of post-install scripts and canister-based infrastructure. However, the exact source of the compromise remains under investigation.

See also  Tether Gold, the World’s Leading Tokenized Gold Product, to be Listed on BNB Chain

Evidence suggests legitimate projects may have been hijacked. Some affected packages have active usage, with one showing over 6,700 weekly downloads. Inconsistencies between npm releases and Git tags further raise suspicion.

Socket said the situation is still evolving, with additional malicious versions continuing to emerge and the full scope of the attack not yet confirmed.

Source link

Attack Chain npm Propagation supply WormLike
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Altcoin supply Is tightening – Traders, is the altseason narrative back?

June 24, 2026

Venus Protocol Launches Tokenized Stock Lending on BNB Chain

June 22, 2026

All about MYX Finance’s 12% drop and $10.4mln supply fear

June 21, 2026

Microsoft Warns of New USB-Based Malware Targeting Crypto Users

June 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Unicoin Staff Locked Out of G-Suite in Mystery Attack

August 19, 2024

Why x402 Could Be the Missing Payment Layer for Blockchain Games

February 16, 2026

LayerZero Hit With Hefty Backlash After ‘Frontrunning’ Lido Governance

October 30, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Fairshake ramps up election spending as CLARITY faces deadline

June 24, 2026

SecondFI’s $2M exploit: A wallet flaw leaves Cardano users exposed

June 24, 2026

Aztec Reaches L2Beat Stage 2 After Governance Revokes Rollup Contract Ownership

June 24, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,571.000.23%
  • ethereumEthereum(ETH)$1,668.800.82%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$576.310.12%
  • usd-coinUSDC(USDC)$1.000.02%
  • rippleXRP(XRP)$1.10-1.30%
  • solanaSolana(SOL)$69.240.72%
  • tronTRON(TRX)$0.328791-0.69%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.15%
  • HyperliquidHyperliquid(HYPE)$62.06-1.62%