Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
- Posted on March 21, 2026
- By The Hacker News
- 9 Views
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

CanisterWorm infects 28 npm packages via ICP-based C2, enabling self-propagation and persistent backdoor access across developer systems.