CanisterWorm infects 28 npm packages via ICP-based C2, enabling self-propagation and persistent backdoor access across developer systems.
Files on a central cloud server used by the ransomware group highlight a systematic, aggressive attack on network backups as a key TTP.