npm · Malicious package advisory
Malware@virtahealth/substrate-root
MAL-2026-2213
Malicious code in @virtahealth/substrate-root (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c8348bbc19210fd9962510b31c4e08572ba739767bd183a4c867071a9a5f9d18) The package @virtahealth/substrate-root was found to contain malicious code. ## Source: google-open-source-security (010efef42ba2d9d54d09099af01e1bf536eedbdb4f873b02785f625a258d3801) This package was compromised by the CanisterWorm campaign by the TeamPCP threat actor. The malicious payload establishes persistence as user systemd service and places a backdoor on the infected host. The malware will also harvest npm credentials and can autonomously spread.
Compromised versions (1)
- 1.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.