TGTGInsighttelegram intelligenceLIVE / telegram public index
← The Hacker News
The Hacker News avatar

TGINSIGHT POST

Post #8855

@thehackernews

The Hacker News

Views8,900Post view count
PostedApr 2204/22/2026, 05:37 PM
Post content

Post content

🛑 Supply chain attacks are stacking across npm, PyPI, and GitHub. CanisterSprawl worm steals npm tokens via postinstall scripts, republishes infected packages, and spreads across ecosystems. Other campaigns add backdoored packages, LLM proxy abuse, and GitHub Actions exploits. 🔗 Read → https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html