StandardsA Self-Propagating Worm Just Proved Your Dependency Security Model Is Broken
Socket and StepSecurity detected a supply chain worm in npm packages that doesn t just steal credentials—it spreads itself. The attack, tracked as CanisterSprawl, uses postinstall hooks to exfiltrate














