Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

April 24, 2026

For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

April 24, 2026

Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

April 24, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

    April 24, 2026

    India pushes digital rupee through welfare pilots as BRICS CBDC plan takes shape

    April 24, 2026

    Bitcoin’s Quantum Problem Is Really A Governance Crisis In Disguise: UTXO

    April 24, 2026

    Eric Trump’s American Bitcoin adds 11,298 ASIC miners – ABTC stock surges 8%

    April 24, 2026

    Will Ethereum Reach $250,000 Before Bitcoin? Here’s What Needs To Happen

    April 24, 2026

    Ethereum Near Key Zone After 36% Gain

    April 24, 2026

    Bitmine Stakes 61,232 ETH Worth $142M

    April 22, 2026

    Ethereum Targets Lower Range As Resistance Zone Comes Into Play

    April 22, 2026

    Bitcoin Recovery May Not Arrive Until October, Scaramucci Says

    April 24, 2026

    Dogecoin Keeps Getting Capped At This Parallel Channel Level, Analyst Says

    April 24, 2026

    What’s Happening Between ETH And The Financial Systems?

    April 24, 2026

    Could Ripple XRP Power Cross-Border Payments? Russia’s Early Tests Suggest Potential

    April 23, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

    April 24, 2026

    For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

    April 24, 2026

    Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

    April 24, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

    April 24, 2026

    Mastercard joins the blockchain security push — why it matters now

    April 24, 2026

    WalletConnect Integrates with TradFi-Focused Chain Canton Network

    April 24, 2026

    Base Tests Azul Upgrade With Multiproofs Ahead of Planned Mainnet Launch

    April 24, 2026

    For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

    April 24, 2026

    Npm Supply Chain Attack Uses Worm-Like Propagation

    April 24, 2026

    How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

    April 22, 2026

    North Korean Blamed for $290m KelpDAO Crypto Heist

    April 21, 2026

    HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

    April 24, 2026

    For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

    April 24, 2026

    Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

    April 24, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026
  • Web 3
    1. Gaming
    2. View All

    KuCoin Launches KuCard in Australia, Expanding Real-World Crypto Payments

    April 24, 2026

    REAL and RWA Inc. Partner to Advance Tokenized Asset Infrastructure Amid Growing RWA Demand

    April 24, 2026

    Zach Lowe: Celtics’ offense struggles since Tatum’s return, Luka Doncic’s historic scoring season, and LeBron’s pivotal role in Lakers’ surprise playoff success

    April 24, 2026

    GameFi is effectively dead as 93% of projects collapse

    April 24, 2026

    HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

    April 24, 2026

    For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

    April 24, 2026

    Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

    April 24, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026

    Justin Sun sues Trump-linked World Liberty over disputed token freeze and governance proposal

    April 24, 2026

    Donald Trump Announces Ceasefire with Iran Extended!

    April 24, 2026

    Tron’s Justin Sun sues Trump-linked World Liberty Financial over frozen assets

    April 24, 2026

    Cardano development teams wants almost $50 million for Bitcoin DeFi and Vision 2030

    April 24, 2026

    Oil tanker attacked after falling for crypto scam granting fake Strait of Hormuz safe passage

    April 21, 2026

    Six years after “DeFi Summer” is the sun already setting on the decentralized finance revolution?

    April 20, 2026

    Bitcoin network activity just hit an 8-year low — has Wall Street replaced retail in the market?

    April 19, 2026

    HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

    April 24, 2026

    For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

    April 24, 2026

    Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

    April 24, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026
  • Analysis

    Can ATOM Price Break Above $2 Resistance?

    April 24, 2026

    Is $2 the Next Target?

    April 24, 2026

    SPK Price Explodes After Breakout, But Overbought Signals Flash Warning

    April 23, 2026

    US Bankers association push for 60 day pause to stop stablecoin rules going live

    April 23, 2026

    STABLE Price Jumps 15% After CEO Spotlight, But Is This Rally Sustainable?

    April 23, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    Over 80% of Bitcoin ETF assets hit Coinbase custody choke point with $74B at risk

    April 13, 2026

    FTX begins $2.2B payout. Can Bitcoin absorb another liquidity test?

    March 31, 2026

    BlinkEx investment platform infrastructure – matching, risk controls, reliability

    March 21, 2026

    Over $2B in “lost” Bitcoin to hit markets this month creating sell pressure within fragile $67k–$74k range

    March 20, 2026

    HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

    April 24, 2026

    For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

    April 24, 2026

    Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

    April 24, 2026

    Labor Secretary Lori Chavez-DeRemer Resigns, Becomes Trump’s Third Cabinet Departure

    April 24, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Npm Supply Chain Attack Uses Worm-Like Propagation
Npm Supply Chain Attack Uses Worm-Like Propagation
Security and Privacy

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across developer ecosystems.

According to new research from Socket, the activity mirrors earlier worm-style supply chain attacks that used blockchain-hosted infrastructure, including Internet Computer Protocol (ICP) canisters, for command and control (C2).

Impacted packages include multiple versions of @automagik/genie and pgserve, both linked to developer tooling workflows. Researchers found the malware executes during installation, harvesting sensitive data and attempting to republish compromised packages using stolen credentials.

Malware Focuses on Sensitive Data

The payload scans infected systems for secrets stored in environment variables and configuration files. Targeted data includes cloud credentials, CI/CD tokens, SSH keys and local developer artifacts such as .npmrc and shell histories.

It also attempts to access browser-stored data and cryptocurrency wallets, including Chrome profiles and extensions like MetaMask and Phantom.

Exfiltration occurs through two channels: a standard HTTPS webhook and an ICP endpoint. Data can be encrypted using AES-256 and RSA methods, though plaintext fallback is possible.

Self-Propagation and Possible Repository Compromise

A key feature of the malware  is its ability to spread. The malware extracts npm tokens, identifies accessible packages, injects malicious code, and republishes them, enabling further compromise across the ecosystem.

It also includes functionality to propagate via Python’s PyPI repository by generating malicious packages using .pth file injection when credentials are present.

Read more on similar threats: Malicious Machine Learning Model Attack Discovered on PyPI

Researchers observed similarities with prior TeamPCP-linked campaigns, including the use of post-install scripts and canister-based infrastructure. However, the exact source of the compromise remains under investigation.

See also  World Mobile Chain Taps Raydium to Thrive in Solana’s DePIN Ecosystem

Evidence suggests legitimate projects may have been hijacked. Some affected packages have active usage, with one showing over 6,700 weekly downloads. Inconsistencies between npm releases and Git tags further raise suspicion.

Socket said the situation is still evolving, with additional malicious versions continuing to emerge and the full scope of the attack not yet confirmed.

Attack Chain npm Propagation Supply WormLike
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

April 24, 2026

WalletConnect Integrates with TradFi-Focused Chain Canton Network

April 24, 2026

How crypto futures markets are feeding ‘scam coin’ insider pump and dumps

April 22, 2026

Banks fund crypto attack ads across Washington as over 3,000 banks unite to stop Clarity Act passing Senate

April 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

BTC Could Move $20K Amid Weak Uptober Rally?

September 25, 2025

First Brands bondholders bring in financial watchdog that probed FTX’s 2022 crash

January 4, 2026

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

HashKey’s tokenization roadmap could reshape Web3 finance — and the agent economy

April 24, 2026

For 93 minutes, installing Bitwarden’s ‘official’ CLI turned laptops into launchpads for hijacking GitHub accounts

April 24, 2026

Crypto Analyst Michaël van de Poppe Says Bitcoin Is Headed Higher – Here Are His Targets

April 24, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.