Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Bitcoin just slipped below the bear-market line traders cannot ignore

June 28, 2026

Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

June 28, 2026

Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

June 28, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

    June 28, 2026

    Crypto bear market isn’t over? AI’s $20B capital rotation says so

    June 28, 2026

    What Robinhood’s recent layoffs say about the current state of crypto investments

    June 28, 2026

    Bitcoin Tests Critical Support As Key Level Hangs In The Balance

    June 28, 2026

    Humanity Protocol, Kelp DAO stolen funds commingle – Same attacker?

    June 28, 2026

    Ethereum ETFs see $12.85M outflows – Why ETH bulls face an uphill battle

    June 28, 2026

    Tether Surpasses Ethereum: A Historic Shift

    June 26, 2026

    Ethereum faces renewed selling pressure: Can key support hold this time?

    June 26, 2026

    Major whale shorts $4.92M in ZEC – Can Zcash rebound to $520?

    June 28, 2026

    XRP Prepares for July Bounce-Back as Price History Points to

    June 28, 2026

    Hyperliquid demand deepens as institutions chase staking yields – Just a fad?

    June 28, 2026

    Whale Activity Shows High-Leverage Short Positions Re-Opened

    June 27, 2026

    Dogecoin Cash Files U.S. Patent for DOGP Blockchain Framework

    June 15, 2026

    How SIREN Went From AI Memecoin to Boom-and-Bust

    June 8, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Bitcoin just slipped below the bear-market line traders cannot ignore

    June 28, 2026

    Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

    June 28, 2026

    Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

    June 28, 2026

    Major whale shorts $4.92M in ZEC – Can Zcash rebound to $520?

    June 28, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Merck and Hashgraph Group launch Hedera-based product passport for EU compliance

    June 12, 2026

    COTI and Midnight Foundation Partner to Advance the Global Privacy Ecosystem

    June 11, 2026

    Cardano Gets Exposure From Olympics Committee

    June 11, 2026

    How Privacy and Composability Trade-Offs Differ

    June 11, 2026

    $47 Million in Illicit Crypto Seized as Europol Cracks Down on Global Cybercrime Networks

    June 27, 2026

    Microsoft Warns of New USB-Based Malware Targeting Crypto Users

    June 21, 2026

    Fake GitHub Stars and AI Videos Mask a Crypto Clipper

    June 18, 2026

    Zcash Climbs 80% Since June 5 as Traders Shrug off Orchard Bug Fears – Bitcoin News

    June 18, 2026

    Bitcoin just slipped below the bear-market line traders cannot ignore

    June 28, 2026

    Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

    June 28, 2026

    Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

    June 28, 2026

    Major whale shorts $4.92M in ZEC – Can Zcash rebound to $520?

    June 28, 2026
  • Web 3
    1. Gaming
    2. View All

    NFT Marketplace Volume Is Concentrating Around the Biggest Players

    June 26, 2026

    Loaded Lions’ Mane City Mobile Heads to iOS and Android as Sign-Ups Begin

    June 23, 2026

    Nexus Acquires Homegrown App Marketplace One Store, Expanding into Global Web3 Game Hub

    June 21, 2026

    GoMining Rolls Out GoBTC Pay SDK for Bitcoin Merchant Payments

    June 20, 2026

    Bitcoin just slipped below the bear-market line traders cannot ignore

    June 28, 2026

    Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

    June 28, 2026

    Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

    June 28, 2026

    Major whale shorts $4.92M in ZEC – Can Zcash rebound to $520?

    June 28, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

    June 28, 2026

    European crypto users are being paid to move before MiCA closes the door

    June 28, 2026

    The UK softened stablecoin rules, but may still be capping its own market

    June 28, 2026

    Outdated bank rules may keep crypto outside the banks now allowed to hold it

    June 27, 2026

    USDT gets a Brazil payment route to 170 million people by making crypto disappear

    June 26, 2026

    UK bond fund ownership records move onto Ethereum and Solana accessible 24/7

    June 26, 2026

    Chainlink’s latest stablecoin push targets the capital stuck in bank FX settlement

    June 25, 2026

    Latest bear market victim shows how quickly DeFi users are left behind when crypto projects move on

    June 24, 2026

    Bitcoin just slipped below the bear-market line traders cannot ignore

    June 28, 2026

    Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

    June 28, 2026

    Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

    June 28, 2026

    Major whale shorts $4.92M in ZEC – Can Zcash rebound to $520?

    June 28, 2026
  • Analysis

    Bitcoin just slipped below the bear-market line traders cannot ignore

    June 28, 2026

    Can Tokenization Narratives Finally Lift Crypto Prices?

    June 27, 2026

    VELVET Price Explodes 250% After Traders Wrote It Off

    June 27, 2026

    Ethereum’s oldest wallets are selling into the $1,500 demand line buyers cannot dodge

    June 27, 2026

    dogwifhat (WIF) Price Rebounds Into Key Supply Zone — Can Bulls Trigger a 30% Breakout?

    June 27, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is BChat? The Decentralized Messaging App Built for Privacy

    June 2, 2026

    What Is an AI Prompt Injection Attack? The Hidden Threat Hijacking Your Chatbots

    May 31, 2026

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    HYPE ETFs quietly pulled $161M in one month as Wall Street buys crypto’s on-chain exchange bet

    June 15, 2026

    Crypto exchanges are opening a two-front war for the stock market

    June 12, 2026

    Crypto’s killer app may be selling stocks after its own tokens failed retail

    June 10, 2026

    Vitalik wants DeFi price crashes to stop triggering automatic liquidations

    June 4, 2026

    Bitcoin just slipped below the bear-market line traders cannot ignore

    June 28, 2026

    Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

    June 28, 2026

    Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

    June 28, 2026

    Major whale shorts $4.92M in ZEC – Can Zcash rebound to $520?

    June 28, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Npm Supply Chain Attack Uses Worm-Like Propagation
Npm Supply Chain Attack Uses Worm-Like Propagation
Security and Privacy

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across developer ecosystems.

According to new research from Socket, the activity mirrors earlier worm-style supply chain attacks that used blockchain-hosted infrastructure, including Internet Computer Protocol (ICP) canisters, for command and control (C2).

Impacted packages include multiple versions of @automagik/genie and pgserve, both linked to developer tooling workflows. Researchers found the malware executes during installation, harvesting sensitive data and attempting to republish compromised packages using stolen credentials.

Malware Focuses on Sensitive Data

The payload scans infected systems for secrets stored in environment variables and configuration files. Targeted data includes cloud credentials, CI/CD tokens, SSH keys and local developer artifacts such as .npmrc and shell histories.

It also attempts to access browser-stored data and cryptocurrency wallets, including Chrome profiles and extensions like MetaMask and Phantom.

Exfiltration occurs through two channels: a standard HTTPS webhook and an ICP endpoint. Data can be encrypted using AES-256 and RSA methods, though plaintext fallback is possible.

Self-Propagation and Possible Repository Compromise

A key feature of the malware  is its ability to spread. The malware extracts npm tokens, identifies accessible packages, injects malicious code, and republishes them, enabling further compromise across the ecosystem.

It also includes functionality to propagate via Python’s PyPI repository by generating malicious packages using .pth file injection when credentials are present.

Read more on similar threats: Malicious Machine Learning Model Attack Discovered on PyPI

Researchers observed similarities with prior TeamPCP-linked campaigns, including the use of post-install scripts and canister-based infrastructure. However, the exact source of the compromise remains under investigation.

See also  2022 – Predictions for the Year Ahead

Evidence suggests legitimate projects may have been hijacked. Some affected packages have active usage, with one showing over 6,700 weekly downloads. Inconsistencies between npm releases and Git tags further raise suspicion.

Socket said the situation is still evolving, with additional malicious versions continuing to emerge and the full scope of the attack not yet confirmed.

Attack Chain npm Propagation Supply WormLike
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

dogwifhat (WIF) Price Rebounds Into Key Supply Zone — Can Bulls Trigger a 30% Breakout?

June 27, 2026

$47 Million in Illicit Crypto Seized as Europol Cracks Down on Global Cybercrime Networks

June 27, 2026

20 transactions, $5.1M transferred to Tornado Cash – Aftermath of the Jaredfromsubway.eth attack

June 24, 2026

Microsoft Warns of New USB-Based Malware Targeting Crypto Users

June 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum Price Signals Market Reset as Binance Open Interest Hits Lowest Levels

March 9, 2026

Is ETH Ready to Moon Akin to Bitcoin and Gold Soon?

October 3, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin just slipped below the bear-market line traders cannot ignore

June 28, 2026

Congress blocks introduction of any CBDC in the next 4 years – but the fight over digital money is just starting

June 28, 2026

Trezor Academy Releases Documentary On Africa’s Bitcoin Economy, Opens Education Donations

June 28, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.