The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

Independent. Nonpartisan. Untested in production.

Tuesday, September 29, 2026 R/PROGRAMMING (TOP)
Reads!

Nine npm lookalikes carried a self-spreading Linux worm

Attackers have disguised nine malicious npm packages as popular Express and React tools, triggering a self-spreading Linux worm during installation.

R/PROGRAMMING (TOP) — The malware establishes a backdoor via Tor and steals SSH access and npm tokens to infect other systems.

When developers install what they believe to be standard Express or React packages, they may unknowingly execute a Linux worm at installation time. This threat spreads through multiple vectors, including SSH connections and Arch User Repository (AUR) packages, because it extracts active credentials such as npm tokens from infected environments.

First, the malware installs a backdoor using the Tor network, which anonymizes the attackers' command traffic. Second, it searches for local keys to hop to other servers, meaning a single compromised development environment can expose an entire internal network.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

◀ Briefs — Page D1

All stories real, just louder · The Daily Commit · Screen edition · Imprint · Privacy Policy