Self-Propagating Supply-Chain Worm Compromises npm Packages to Harvest Developer Tokens
Researchers uncovered a self-spreading supply-chain worm that hijacks npm packages, steals developer tokens and secrets, and pushes poisoned releases. The campaign, tracked as CanisterSprawl, also includes PyPI propagation and links to other recent attacks on open-source package registries.