{"type":"bundle","id":"bundle--70a0747a-5bbc-5789-a142-92c04d62e6c5","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--81c57d58-4608-5634-b414-b74a5ccc2740","created":"2026-08-09T11:30:00.000Z","modified":"2026-08-09T11:20:00.000Z","name":"CanisterWorm npm publisher compromise","description":"Socket documented a worm-enabled npm supply-chain campaign that abused legitimate publisher access, replaced package contents with install-time malware, and propagated through stolen publishing credentials.","aliases":["CanisterWorm"],"first_seen":"2026-03-20T00:00:00.000Z","last_seen":"2026-03-23T00:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Socket: CanisterWorm campaign","url":"https://socket.dev/supply-chain-attacks/canisterworm"}]}]}