CanisterWorm npm publisher compromise
Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.
Also tracked as CanisterWorm
- First observed
- Mar 20, 2026
- Last observed
- Mar 23, 2026
- Last reviewed
- Sep 2, 2026
- Tracking ended
- Sep 8, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
The reviewed campaign page reports a bounded affected-package set and last activity through March 23, 2026. Later registry remediation or newly linked artifacts may change that set.
- Publisher-account recovery, token revocation, registry action, and endpoint cleanup remain necessary when a malicious package has already executed.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
partial
Eligible package-install intent can be reviewed by Guard, but compromised publisher credentials, registry-side propagation, and malware that already executed are outside the complete local interception boundary.
- Recipe available
Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- First observed
CanisterWorm npm publisher compromise was first observed in the reviewed source material.
- Disclosure
The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 3347.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
CanisterWorm reviewed package setnpmpackage
Sources
Every claim on this record is traceable to the sources below.
Record HGTC-2026-CANISTER26