New npm Attack: How a Self-Spreading Worm Compromises Credentials (What Developers Must Do) (2026)

A new supply chain attack targeting the Node Package Manager (npm) ecosystem has emerged, stealing developer credentials and spreading through compromised accounts. This attack, discovered by researchers at Socket and StepSecurity, targets high-value endpoints in AI agent tooling and database operations. The injected malicious code collects sensitive data, including tokens, API keys, SSH keys, cloud service credentials, and cryptocurrency wallets. What makes this attack particularly insidious is its worm-like function, enabling it to spread quickly and recursively through affected packages. The malicious script identifies packages with publish tokens and republishes them with an increased version number, further propagating the compromise. This multi-ecosystem attack also targets Python packages using a .pth-based payload. Developers are urged to treat all listed package versions as malicious and remove them from systems and CI/CD pipelines. Socket and StepSecurity provide indicators of compromise and recommended actions to help defenders identify and mitigate this threat. The attack highlights the ongoing challenges in securing software supply chains and the need for proactive security measures to protect against sophisticated threats.

New npm Attack: How a Self-Spreading Worm Compromises Credentials (What Developers Must Do) (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Fr. Dewey Fisher

Last Updated:

Views: 5907

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Fr. Dewey Fisher

Birthday: 1993-03-26

Address: 917 Hyun Views, Rogahnmouth, KY 91013-8827

Phone: +5938540192553

Job: Administration Developer

Hobby: Embroidery, Horseback riding, Juggling, Urban exploration, Skiing, Cycling, Handball

Introduction: My name is Fr. Dewey Fisher, I am a powerful, open, faithful, combative, spotless, faithful, fair person who loves writing and wants to share my knowledge and understanding with you.