CanisterSprawl: self-propagating npm worm hits pgserve + Namastex packages
Socket and StepSecurity disclosed CanisterSprawl, a self-propagating npm worm that compromised at least 16 versions across Namastex Labs and related publishers from 21 April 2026. The postinstall hook harvests 38 env vars and filesystem secrets, encrypts via AES-256-CBC + RSA-4096, and exfiltrates to an Internet Computer Protocol canister. Stolen npm tokens are reused to publish further malicious versions. Tradecraft matches the earlier TeamPCP CanisterWorm campaign.
Versions named here: 1.1.11, 1.1.12, 1.1.13