On 21 April 2026 malicious versions of pgserve, an embedded PostgreSQL server for Node.js, appeared on npm with a credential stealer that also behaved as a worm. StepSecurity and Socket, which track the campaign as CanisterSprawl, found the same malware in packages from Namastex Labs, an agentic AI company, and in packages from other publishers. The payload ran at install time and harvested npm, GitHub, cloud, SSH and other credentials. It sent them to a webhook and to a decentralised Internet Computer (ICP) canister, which StepSecurity notes cannot be taken down by domain seizure. Its key feature was propagation. When it found an npm publish token, it republished every package that token could publish with the malware inside. When it found PyPI credentials, it tried the same on PyPI. Socket found a strong overlap with TeamPCP's earlier CanisterWorm, including a code reference to a "TeamPCP/LiteLLM method", but has not attributed the campaign. How the first package was compromised is not known.
Key takeaways
- pgserve 1.1.11 to 1.1.13 were published on 21 April 2026 without matching git tags, carrying a
postinstallcredential stealer, according to StepSecurity. Socket found the same payload in seven @automagik/genie versions and in @fairwords and @openwebconcept packages. - The worm looked for npm tokens in
NPM_TOKENand~/.npmrc, listed every package each token could publish, bumped the patch version, injected itself and republished. With PyPI credentials it built and uploaded malicious Python packages. - The stealer took environment secrets matching about 40 patterns, plus
.npmrc,.netrc, SSH keys, cloud credentials, Chrome saved passwords and wallet files, and exfiltrated them to an ICP canister. - The malicious releases are confirmed by multiple researchers. Attribution and the initial access route are not: Socket calls it TeamPCP-style but stops short of naming the group.
- The identity lesson: a publish token is a key to every package it can reach, so one token on one developer laptop can become dozens of compromised packages.
At a glance
| Organisations | Namastex Labs (pgserve, @automagik/genie); publishers of @fairwords and @openwebconcept packages; developers and pipelines that installed affected versions |
|---|---|
| When | First malicious pgserve version at 22:14 UTC on 21 April 2026; reported 21 and 22 April 2026 |
| Attacker | Unattributed; Socket reports strong overlap with TeamPCP's CanisterWorm |
| Entry point | Unknown initial compromise of the first publisher; then npm publish tokens stolen from each victim |
| Identities abused | npm publish tokens and PyPI credentials; then GitHub tokens, cloud keys, SSH keys and other secrets on infected machines |
| Impact | Malicious versions across at least six npm packages from three publisher namespaces; credentials stolen from systems that installed them |
| Category | NHI. Incident class: confirmed NHI breach (stolen publish tokens used to republish malicious packages) |
What happened
StepSecurity flagged three new pgserve releases, 1.1.11, 1.1.12 and 1.1.13, all published on 21 April 2026 with no matching git tag. The last legitimate version, 1.1.10, was published with a tag on 17 April. Each new release added two files, a script and an attacker's RSA public key. The postinstall hook ran the script and ended in || true, which StepSecurity called "an intentional silencing mechanism" because the install looks clean either way. In a controlled run the script harvested 38 environment variables and sent about 4.4 KB of encrypted data to an ICP canister. StepSecurity says the canister "cannot be taken down by law enforcement or domain seizure". A second exfiltration endpoint, a webhook, was used only when a specific environment variable was set.
Socket widened the picture the next day. It found the malware in @automagik/genie 4.260421.33 to 4.260421.39, a Namastex package with about 6,744 weekly downloads, and in pgserve. It also found it in @fairwords/websocket and @fairwords/loopback-connector-es, which it describes as previously compromised, and in @openwebconcept/design-tokens and @openwebconcept/theme-owc, which it calls victim packages. The Hacker News lists further versions of pgserve and @automagik/genie found later. Socket wrote: "It is designed to turn one compromised developer environment into additional package compromises." The payload extracted npm tokens, found every package the victim could publish, injected the hook into those tarballs and republished them. If PyPI credentials were present, it generated a .pth payload that runs on every Python start and uploaded malicious packages with Twine.
On attribution, Socket said: "There is a strong overlap in technique, code lineage, and threat actor tradecraft." The overlap is with CanisterWorm, which spread through npm with tokens stolen after the Trivy compromise in March. The payload even contains an explicit reference to a "TeamPCP/LiteLLM method" for .pth injection. But the canister is a different one, and Socket did not name the actor. Socket also said "the upstream cause remains unresolved": nobody has published how the first Namastex package was compromised. None of the sources includes a statement from Namastex Labs.
Timeline
| Date | Event |
|---|---|
| 22 March 2026 | Wiz reports TeamPCP's CanisterWorm spreading through npm with credentials stolen after the Trivy compromise. |
| 17 April 2026 | pgserve 1.1.10, the last legitimate release, is published with a git tag. |
| 21 April 2026 | Malicious pgserve 1.1.11 (22:14 UTC), 1.1.12 (22:26 UTC) and 1.1.13 are published; StepSecurity reports the compromise. |
| 22 April 2026 | Socket links the malware to Namastex, @fairwords and @openwebconcept packages; The Hacker News and The Register report the worm. |
| 23 April 2026 | GitGuardian groups CanisterSprawl with the Checkmarx KICS and xinference attacks as three campaigns in 48 hours. |
How it happened: the identity attack path
- A first publisher compromised. An attacker gained the ability to publish pgserve and @automagik/genie. How is not known, but the releases had no matching git tags, so they did not come from the normal release process.
- Install-time execution. A
postinstallhook ran the stealer on everynpm install, on developer machines and CI runners alike. - Publish tokens harvested. The stealer read npm tokens from
NPM_TOKENand~/.npmrc, along with GitHub, cloud and SSH credentials. - Every reachable package republished. For each token it listed the packages the token could publish, injected itself and pushed a new patch version, so each victim became a new distributor.
- Jump to PyPI. Where PyPI credentials existed, it built and uploaded malicious Python packages with a
.pthpayload.
Impact
- Confirmed: malicious versions of pgserve, @automagik/genie, two @fairwords packages and two @openwebconcept packages, according to Socket and StepSecurity.
- Confirmed exfiltration path: StepSecurity observed the canister accept encrypted data in its controlled run.
- Potential: theft of npm, PyPI, GitHub, cloud, SSH and browser-stored credentials from every system that installed an affected version, and further package compromises using stolen publish tokens. No victim count has been published.
- Unknown: the initial access route and the full list of packages republished by the worm.
What this means for NHI governance
CanisterSprawl is a worm built on one kind of non-human identity: the package publish token. A classic npm token is a bearer credential that can publish every package its owner maintains. It often sits in a plain-text ~/.npmrc or a CI environment variable for months. Any code that runs during an install can read it. This is the same pattern as the 2025 Shai-Hulud npm worm and the 2026 ChainDrop worm. Each victim's token becomes the next infection.
The answer is to make publish tokens rare, narrow and short-lived. Trusted publishing with OIDC issues a token to a specific CI workflow for a specific release. Granular tokens limit which packages a credential can touch. Keeping publishing credentials off developer machines removes the easiest place to steal them. See our CI/CD Pipeline Identity Security Guide, Secrets Management Guide and API Key Management Guide.
Recommendations
- Remove affected versions and rotate. Pin pgserve to 1.1.10 or earlier, remove affected @automagik/genie, @fairwords and @openwebconcept versions, and rotate npm, GitHub, cloud and SSH credentials on systems that installed them. See our Leaked Credential Response Playbook.
- Get publish tokens off developer machines. Remove
_authTokenentries from~/.npmrcand publish only from CI with trusted publishing. See our CI/CD Pipeline Identity Security Guide. - Scope tokens to single packages. Where a token is unavoidable, use a granular token limited to one package and a short expiry. See our API Key Management Guide.
- Audit your publish history. Check for versions you did not release, especially patch bumps with no git tag, and compare npm tarballs with tagged source.
- Disable install scripts by default. Use
ignore-scriptsin CI and allow scripts only for packages that need them. - Watch egress from build systems. Block or alert on connections from CI runners and developer tools to unknown endpoints, including ICP canister domains. See our Secrets Management Guide.
Frequently asked questions
What is CanisterSprawl?
CanisterSprawl is the name Socket and StepSecurity use for a self-propagating npm worm first seen in malicious pgserve versions on 21 April 2026. It steals credentials at install time, sends them to an Internet Computer canister and uses stolen npm and PyPI tokens to republish the victim's own packages with the malware.
Is CanisterSprawl the work of TeamPCP?
Not confirmed. Socket found strong overlap with TeamPCP's CanisterWorm, including a code reference to a "TeamPCP/LiteLLM method", but the canister is different and Socket stopped short of attributing it.
Which packages were affected by CanisterSprawl?
Socket lists pgserve 1.1.11 to 1.1.13, @automagik/genie 4.260421.33 to 4.260421.39, @fairwords/websocket 1.0.38 and 1.0.39, @fairwords/loopback-connector-es 1.4.3 and 1.4.4, and @openwebconcept/design-tokens and @openwebconcept/theme-owc 1.0.3. Later reports added further versions.
Related NHI Mgmt Group resources
Shai-Hulud npm Worm 2025 · Trivy supply chain attack 2026 · Bitwarden CLI npm compromise 2026 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Package publish tokens are among the most dangerous credentials a developer holds, and among the least governed. We help teams find them, replace them with trusted publishing and build response plans for worm-style outbreaks. See our NHI and AI agent security training.
References
- StepSecurity: CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister (21 April 2026)
- Socket: Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware (22 April 2026)
- The Hacker News: Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens (22 April 2026)
- The Register: Another npm supply chain worm is tearing through dev environments (22 April 2026)
- GitGuardian: No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours (23 April 2026)