Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

May 18, 2026

TON’s agentic wallets turn Telegram bots into spending entities

May 18, 2026

Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

May 17, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

    May 17, 2026

    Poland Passes Crypto Bill As Fraud Probe Deepens Political Divide

    May 17, 2026

    Bitcoin: Can the Fed’s $26.3B liquidity injection stop BTC’s $60K retest?

    May 17, 2026

    DMND And RootstockLabs Partner To Bring Stratum V2 To Merge-mining

    May 17, 2026

    Ethereum Triangle Breakdown Adds Pressure On Its Recovery Outlook

    May 17, 2026

    Ethereum Network Registers Strongest Profit Realization In Weeks — What This Means

    May 15, 2026

    Ethereum Price Reaching $4,000 Isn’t A Moonshot, Here’s What It Is

    May 15, 2026

    Ethereum Exchange Balances Rise Sharply

    May 15, 2026

    Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

    May 18, 2026

    XRP Will Go ‘Higher, Much Higher,’ Analyst Says, Betting On Explosive Breakout

    May 17, 2026

    What This Solana’s 108% Growth Means For The Price

    May 17, 2026

    Bitcoin Struggles Below Resistance While Fibonacci Support Comes Into Focus

    May 17, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

    May 18, 2026

    TON’s agentic wallets turn Telegram bots into spending entities

    May 18, 2026

    Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

    May 17, 2026

    US and Bolivia Target the ‘Modern Pablo Escobar’ in Massive Crypto Laundering Probe

    May 17, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    TON’s agentic wallets turn Telegram bots into spending entities

    May 18, 2026

    Kyber Network Launches Smart Settlement to Reduce Slippage on EVM Chains

    May 17, 2026

    Stables Expands USDT Settlement Network

    May 17, 2026

    Alchemy Chain Unveils Roadmap for Dual-Compliant Stablecoin Payment Network

    May 17, 2026

    THORChain exploit turns emergency chain halt into a DeFi trust test

    May 16, 2026

    Ripple insider warns XRP holders as fake airdrop scams surge across XRPL

    May 14, 2026

    Ripple Shares DPRK Threat Data on Fraud Domains, Wallets, Campaigns

    May 5, 2026

    Digital Asset Security Moves Beyond Keys as Bitgo Adds 5-Layer Checks

    May 1, 2026

    Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

    May 18, 2026

    TON’s agentic wallets turn Telegram bots into spending entities

    May 18, 2026

    Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

    May 17, 2026

    US and Bolivia Target the ‘Modern Pablo Escobar’ in Massive Crypto Laundering Probe

    May 17, 2026
  • Web 3
    1. Gaming
    2. View All

    CLARITY Act and Blockchain Gaming: 2026 Impact Explained

    May 15, 2026

    The Human Patch: How Ethereum’s Clear Signing Standard Is Tackling Crypto’s Most Exploited Vulnerability

    May 14, 2026

    NUMINE Joins Outer Ring MMO for the Expansion of Web3 Gaming Experiences

    May 13, 2026

    GMatrixs And MiniverseCore Join Forces To Unlock Web3 Gaming Experience With Cross-Chain DApp, DeFi Applications

    May 11, 2026

    Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

    May 18, 2026

    TON’s agentic wallets turn Telegram bots into spending entities

    May 18, 2026

    Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

    May 17, 2026

    US and Bolivia Target the ‘Modern Pablo Escobar’ in Massive Crypto Laundering Probe

    May 17, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    US and Bolivia Target the ‘Modern Pablo Escobar’ in Massive Crypto Laundering Probe

    May 17, 2026

    CLARITY Act is not law yet, but the markup is a major retail adoption trust catalyst

    May 17, 2026

    Ripple Exec Cheers Crypto Bill Vote

    May 17, 2026

    Australia’s proposed CGT changes could discourage long term crypto holding

    May 17, 2026

    Societe Generale pushes stablecoins into Canton repo and collateral rails

    May 17, 2026

    Tether launches decentralized local AI using Isaac Asimov’s Psychohistory straight out of Foundation

    May 11, 2026

    Has Donald Trump been a net positive for Bitcoin or created an unbreakable partisan divide?

    May 10, 2026

    BlackRock looks to sidestep Clarity yield issues, filing for two new tokenized money market funds

    May 10, 2026

    Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

    May 18, 2026

    TON’s agentic wallets turn Telegram bots into spending entities

    May 18, 2026

    Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

    May 17, 2026

    US and Bolivia Target the ‘Modern Pablo Escobar’ in Massive Crypto Laundering Probe

    May 17, 2026
  • Analysis

    Bitcoin ETF flows reverse as funds shed $1B on inflation fears

    May 16, 2026

    SUI Network Sees Whale Accumulation Ahead of Gasless Upgrade

    May 16, 2026

    Why Is Bittensor (TAO) Price Crashing Today?

    May 16, 2026

    LAB Price Rebounds Hard After 60% Crash as Mobile App Launch Fuels Speculation

    May 16, 2026

    ASTEROID Price Coils As SpaceX Mascot Memecoin Eyes Breakout

    May 16, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Is AI Jailbreaking? A Beginner’s Guide to the Cat-and-Mouse Game Behind Every Chatbot

    May 17, 2026

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    Kraken moves Bitcoin to Chainlink as bridge fears spread across DeFi

    May 16, 2026

    Coinbase went down for over 5 hours after missing earnings. Bulls still see a path to $300 billion by 2030

    May 8, 2026

    Coinbase cuts 14% of staff as Armstrong ties cost reset to AI and market volatility

    May 6, 2026

    Bitcoin is still in charge

    May 3, 2026

    Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

    May 18, 2026

    TON’s agentic wallets turn Telegram bots into spending entities

    May 18, 2026

    Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

    May 17, 2026

    US and Bolivia Target the ‘Modern Pablo Escobar’ in Massive Crypto Laundering Probe

    May 17, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Npm Supply Chain Attack Uses Worm-Like Propagation
Npm Supply Chain Attack Uses Worm-Like Propagation
Security and Privacy

Npm Supply Chain Attack Uses Worm-Like Propagation

April 24, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across developer ecosystems.

According to new research from Socket, the activity mirrors earlier worm-style supply chain attacks that used blockchain-hosted infrastructure, including Internet Computer Protocol (ICP) canisters, for command and control (C2).

Impacted packages include multiple versions of @automagik/genie and pgserve, both linked to developer tooling workflows. Researchers found the malware executes during installation, harvesting sensitive data and attempting to republish compromised packages using stolen credentials.

Malware Focuses on Sensitive Data

The payload scans infected systems for secrets stored in environment variables and configuration files. Targeted data includes cloud credentials, CI/CD tokens, SSH keys and local developer artifacts such as .npmrc and shell histories.

It also attempts to access browser-stored data and cryptocurrency wallets, including Chrome profiles and extensions like MetaMask and Phantom.

Exfiltration occurs through two channels: a standard HTTPS webhook and an ICP endpoint. Data can be encrypted using AES-256 and RSA methods, though plaintext fallback is possible.

Self-Propagation and Possible Repository Compromise

A key feature of the malware  is its ability to spread. The malware extracts npm tokens, identifies accessible packages, injects malicious code, and republishes them, enabling further compromise across the ecosystem.

It also includes functionality to propagate via Python’s PyPI repository by generating malicious packages using .pth file injection when credentials are present.

Read more on similar threats: Malicious Machine Learning Model Attack Discovered on PyPI

Researchers observed similarities with prior TeamPCP-linked campaigns, including the use of post-install scripts and canister-based infrastructure. However, the exact source of the compromise remains under investigation.

See also  Bitcoin Thieves Hit Cashaa - Infosecurity Magazine

Evidence suggests legitimate projects may have been hijacked. Some affected packages have active usage, with one showing over 6,700 weekly downloads. Inconsistencies between npm releases and Git tags further raise suspicion.

Socket said the situation is still evolving, with additional malicious versions continuing to emerge and the full scope of the attack not yet confirmed.

Attack Chain npm Propagation Supply WormLike
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Alchemy Chain Unveils Roadmap for Dual-Compliant Stablecoin Payment Network

May 17, 2026

THORChain exploit turns emergency chain halt into a DeFi trust test

May 16, 2026

BNB Chain Unveils On-Chain Agent Identity and Payment Framework With ERC-8004 Standard

May 16, 2026

Upbit to Launch Proprietary Wallet and Blockchain Chain, Signaling Shift to On-Chain Platform

May 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

CLARITY Act Faces Senate Hurdles Over Trump Family Crypto Conflicts, Passage Could Slip to 2027

May 13, 2026

U.S. Watchdog Targets Cross-Border Fraud with Dedicated Unit

September 9, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Binance Records $1.5 Billion Stablecoin Net Inflow Amid Highly Reactive Market

May 18, 2026

TON’s agentic wallets turn Telegram bots into spending entities

May 18, 2026

Bitcoin ETFs lose $1.54B in a week – Is BTC demand slowing down?

May 17, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.