Reviewed threat campaign

CanisterWorm npm publisher compromise

Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.

Severity highConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

The reviewed campaign page reports a bounded affected-package set and last activity through March 23, 2026. Later registry remediation or newly linked artifacts may change that set.

Limitations

Timeline

  1. · CanisterWorm npm publisher compromise was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 3347.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources