Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
A self-propagating npm worm called CanisterSprawl steals developer tokens to autonomously spread malicious code across packages. It uses blockchain infrastructure for command-and-control, demonstrating a new escalation in supply chain attacks targeting the Node.js ecosystem.