Reviewed threat campaign
CanisterWorm npm publisher compromise
Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.
Uncertainty
The reviewed campaign page reports a bounded affected-package set and last activity through March 23, 2026. Later registry remediation or newly linked artifacts may change that set.
Limitations
- Publisher-account recovery, token revocation, registry action, and endpoint cleanup remain necessary when a malicious package has already executed.
Timeline
- · CanisterWorm npm publisher compromise was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 3347.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:codex — Eligible package-install intent can be reviewed by Guard, but compromised publisher credentials, registry-side propagation, and malware that already executed are outside the complete local interception boundary.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Sources
- Socket: CanisterWorm campaign · observed 2026-08-09