Photo by Arif Riyanto on Unsplash. Source: https://unsplash.com/photos/boy-in-front-of-computer-monitor-vJP-wZ6hGBg (Unsplash License).

Package registries have become an attack surface with a public write path. A worm that can publish does not need a vulnerable library. It becomes the dependency, and the registry turns into the delivery mechanism for every downstream install, cache, and build that trusts it.

  • Self-propagating. Fix one package and the worm pushes back.
  • Earlier versions deleted home directories. Later ones went after coding-agent credentials (Claude, Codex, Cursor, Gemini).
  • Supply-chain scanners catch what is known. They do not protect you from what ships tonight.

Full write-up. The npm Worm That Puts Itself Back Every Time You Patch a Package

Supply chain accountability runs through this. The 2026 State of Enterprise Infrastructure report covers what organisations are actually absorbing and which tooling holds up.

By Tech Thought Leaders

Independent analysis of cloud-native infrastructure, virtualization and data centre economics.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.