Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
✦ NabkaNews BriefAuto-summarized from multiple outlets · verify with the source
A supply chain attack has been reported, involving the Trivy security scanner, which has triggered a self-spreading CanisterWorm across multiple npm packages. The attack appears to have been carried out by a group, with some reports suggesting they used the Trivy scanner as a weapon against developers. The scope of the attack and its full impact are not entirely clear, with reports indicating it may be part of a larger campaign.