Cybersecurity researchers have flagged a fresh set of packages
that have been compromised by bad actors to deliver a
self-propagating worm that spreads through stolen developer npm
tokens. The supply chain worm has been detected by both Socket and
StepSecurity, with the companies tracking the activity under the
name CanisterSprawl owing to the use of an ICP canister to
exfiltrate the stolen data
Read more https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html

