top of page
This site was designed with the
.com
website builder. Create your website today.
Start Now
Home
Posts
About
More
Use tab to navigate through the menu items.
Explain IT Again
Search
ALL POSTS
All Posts
News
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
Key Findings * TeamPCP cybercriminal group suspected behind supply chain attack * 47 npm packages compromised across multiple scopes * Self-propagating CanisterWorm uses ICP blockchain canister as command-and-control infrastructure * Attack leverages npm package postinstall hooks to execute malware * Worm can automatically spread using stolen npm authentication tokens * Decentralized C2 infrastructure makes takedown efforts difficult Background The supply chain attack targets
Mar 21
2 min read
bottom of page