Security News Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages TheHackerNews Daniel Bender 21 Mar 2026 CanisterWorm infects 28 npm packages via ICP-based C2, enabling self-propagation and persistent backdoor access across developer systems.