Nine npm packages published by user dirtyblanket on September 29, 2026, contain a self-spreading Linux worm that impersonates Express and React frameworks. The worm installs a backdoor, propagates via SSH keys and npm tokens, and uses the Wayback Machine to evade detection.
Nine malicious npm packages published by the dirtyblanket account on September 29, 2026, distribute a self-propagating Linux worm that installs a backdoor, steals SSH keys and npm tokens, and spreads via compromised machines to AUR packages and new npm versions. The worm uses a preinstall hook to download and execute a payload through the Internet Archive Wayback Machine, evading allowlists and version pinning.