CanisterWorm is a self-propagating malware family associated with TeamPCP that spread through software supply-chain compromises, particularly the npm ecosystem, and later appeared in Kubernetes-focused intrusions. It is notable for using Internet Computer Protocol canisters as decentralized command-and-control infrastructure, an approach that complicates conventional takedown and sinkholing efforts.
The malware propagated by harvesting stolen npm publish tokens, identifying packages the compromised identity could update, incrementing package versions, and publishing trojanized releases at high speed across multiple publisher scopes. In infected developer environments, it deployed persistence mechanisms that masqueraded as benign system services and periodically resolved follow-on payload locations through the ICP-based dead-drop channel. Reported variants also preserved package metadata and restored original files after publishing, indicating operational emphasis on stealth and continued propagation.
CanisterWorm has been observed targeting Linux and Kubernetes environments. In cluster intrusions, it propagated through reachable Kubernetes contexts and deployed privileged workloads for cluster-wide execution. It has been described as masquerading as systemd services and PostgreSQL-related utilities, and as supporting broader worm-like spread through cloud-native environments. High-confidence reporting also links some variants to destructive behavior: systems matching Iran-related locale or timezone conditions were subjected to recursive file deletion or cluster-wide wiping, while non-matching Kubernetes nodes received backdoor-style persistence instead.
The malware’s role in TeamPCP operations places it at the intersection of credential theft, persistence, propagation, and destructive post-compromise activity. It has been used both as an npm worm seeded by stolen CI/CD credentials and as a follow-on payload in Kubernetes breaches, making it a significant example of supply-chain-enabled worming in modern developer and cloud infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
19 mars 2026 : Compromission de Trivy (scanner de vulnérabilités Aqua Security) via un tag malveillant v0.69.4 ( CVE-2026-33634 , CVSS v4 : 9.4). Propagation via GitHub Releases, Docker Hub, AWS ECR et GitHub Container Registry en ~4 heures.
Initial Access: Exploiting public-facing applications (e.g., React2Shell) and exposed APIs (Docker, Kubernetes, Redis, Ray dashboards).
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
Aikido Security - TeamPCP deploys CanisterWorm on NPM ... CanisterWorm — Self-propagating worm using ICP Canister for C2 ... File System Indicators /tmp/pglog (CanisterWorm payload drop path)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On Kubernetes nodes located outside of Iran, it deployed the CanisterWorm backdoor.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
La campagne repose sur un modèle de compromission en cascade : les credentials volés lors d’une intrusion servent à accéder aux systèmes suivants.
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
the threat actor TeamPCP compromised Aqua Security’s Trivy vulnerability scanner, its GitHub Actions, and over 60 npm packages in a multi-phase open source software supply chain attack.
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting...
La campagne repose sur un modèle de compromission en cascade : les credentials volés lors d’une intrusion servent à accéder aux systèmes suivants.
the malware uses passwordless sudo to dump Runner.Worker process memory via /proc/[pid]/mem, parsing readable memory regions and searching for {"value":"<secret>","isSecret":true}
La campagne repose sur un modèle de compromission en cascade : les credentials volés lors d’une intrusion servent à accéder aux systèmes suivants.
the malware exfiltrated stolen data to the vendor-themed typosquat domain checkmarx[.]zone .
SANDCLOCK scraped secrets from CI runner memory and transmitted AWS keys, GitHub tokens, Kubernetes configurations, and SSH private keys to attacker-controlled infrastructure.
It also swept 50+ filesystem paths for SSH keys, AWS/GCP/Azure credentials, Kubernetes tokens, Docker configs, and cryptocurrency wallets.
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
CanisterWorm uses a decentralized Internet Computer Protocol (ICP) canister for C2, providing a tamper-proof dead-drop for payload delivery
Exfiltration chiffrée AES-256-GCM + RSA vers un endpoint imitant Checkmarx, avec dead-drop sur des dépôts GitHub aux noms thématiques Dune.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor used on non-Iranian Kubernetes nodes after compromise, apparently as part of TeamPCP's automated and self-propagating post-exploitation tooling.
A worm deployed via stolen npm tokens that used an ICP canister as decentralized command-and-control infrastructure.
A malware/wiper referenced as attacking Iranian machines and wiping them clean.
A self-propagating npm worm that steals npm tokens, republishes compromised packages, installs persistence via a systemd user service, and deploys a Python backdoor that polls an ICP canister for updated payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.