MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Namastex Labs npm packages compromised by self-propagating CanisterWorm malware

On 21 April 2026, malicious releases of legitimate npm packages associated with Namastex Labs, including pgserve and Automagik Genie, were distributed through trusted package channels. Researchers found install-time malware that harvested developer, cloud, CI/CD, npm and PyPI credentials and was capable of using stolen publishing tokens to inject itself into additional packages. StepSecurity confirmed active exfiltration behavior during controlled analysis. The compromise therefore altered legitimate upstream software artifacts and created a direct software-supply-chain data-integrity impact for downstream installations.

69

Estimated severity

69 / 100

91

Source reliability

91 / 100

Approximate Date

21/04/2026

Targeted Company

NAMASTEX LABS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Brazil

BRA

Other Affected Countries

No other affected countries reported

Target country

Brazil

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalware

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.