Home / Mar 22, 2026 / Story
0
#2 The Hacker News general March 21, 2026 at 07:28 UTC

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

By [email protected] (The Hacker News)

AI Summary

Following the Trivy scanner compromise, the same attackers deployed CanisterWorm, a self-propagating worm that infected 47 npm packages using ICP canisters (smart contracts on the Internet Computer Protocol). The malware demonstrates sophisticated supply chain attack techniques by leveraging tamperproof smart contracts for persistence and propagation across the JavaScript ecosystem.

Relevance score: 90.0/100

# More from March 22