{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-CANISTER26","slug":"canisterworm-npm-publisher-compromise","title":"CanisterWorm npm publisher compromise","aliases":["CanisterWorm"],"summary":"Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.","status":"published","severity":"high","confidence":"high","uncertainty":"The reviewed campaign page reports a bounded affected-package set and last activity through March 23, 2026. Later registry remediation or newly linked artifacts may change that set.","firstObservedAt":"2026-03-20T00:00:00.000Z","lastObservedAt":"2026-03-23T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:socket-canisterworm","label":"Socket: CanisterWorm campaign","url":"https://socket.dev/supply-chain-attacks/canisterworm","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:canisterworm-npm","artifactClass":"package","ecosystem":"npm","name":"CanisterWorm reviewed package set","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-03-20T00:00:00.000Z","eventType":"first_observed","summary":"CanisterWorm npm publisher compromise was first observed in the reviewed source material.","sourceIds":["source:socket-canisterworm"]},{"id":"timeline:disclosure","occurredAt":"2026-03-23T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:socket-canisterworm"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Eligible package-install intent can be reviewed by Guard, but compromised publisher credentials, registry-side propagation, and malware that already executed are outside the complete local interception boundary."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."}],"limitations":["Publisher-account recovery, token revocation, registry action, and endpoint cleanup remain necessary when a malicious package has already executed."],"correctionHref":"/guard/security/campaigns/canisterworm-npm-publisher-compromise/corrections"}