Fake Express Packages on NPM Spread Linux Worm
Fake Express packages on NPM spread a Linux worm, posing a significant security risk for engineers.
Nine npm packages conceal a self-replicating Linux worm. Published by 'dirtyblanket' on September 29, 2026, these packages mimic popular Express and React frameworks. Installing a package on Linux initiates the worm, which spreads via SSH keys and npm tokens by installing a backdoor.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work