The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm. The name is a reference to
โกQuick SummaryAI generating...
I
info@thehackernews.com (The Hacker News)
๐ก
Original Source
The Hacker News
https://thehackernews.com/2026/03/trivy-supply-chain-attack-triggers-self.htmlThe threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm.
The name is a reference to the fact that the malware uses an ICP canister, which refers to tamperproof smart contracts on
Tags:#security#the-hacker-news
Found this useful? Share it!
Read the Full Story
Continue reading on The Hacker News
Related Stories

๐Security
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
about 6 hours ago

๐Security
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
about 9 hours ago

๐Security
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
about 11 hours ago

๐Security
Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw
about 24 hours ago
