Fetching from the wire…
01
02
03
04
05
06
07
08
Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.
CanisterWorm supply chain attack crosses from npm to PyPI.
Source findingTeamPCP expanded operations to npm ecosystem via CanisterWorm worm using stolen publish tokens.
Source findingTeamPCP expanded operations to npm ecosystem via CanisterWorm worm using stolen publish tokens.
Source finding