Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
- Posted on April 22, 2026
- By The Hacker News
- 0 Views
- 1 min read
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens

Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks.