CanisterWorm is a self-propagating npm supply-chain worm associated with the financially motivated TeamPCP activity cluster. It was distributed through trojanized npm package updates using lifecycle scripts, including postinstall execution, to deploy a Python-based backdoor on affected systems. The worm harvests npm authentication tokens, identifies packages for which the compromised identity has publishing permissions, and automatically publishes malicious patch-version updates to extend propagation across publisher scopes. CanisterWorm also targets cloud credentials, API keys, and other developer secrets. It uses Internet Computer Protocol canisters as decentralized command-and-control infrastructure and has been observed establishing Linux persistence by masquerading as legitimate system services and utilities. Variants operating in Kubernetes environments have deployed backdoors, attempted propagation through accessible infrastructure, and performed destructive recursive deletion in affected clusters.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
19 mars 2026 : Compromission de Trivy (scanner de vulnérabilités Aqua Security) via un tag malveillant v0.69.4 ( CVE-2026-33634 , CVSS v4 : 9.4). Propagation via GitHub Releases, Docker Hub, AWS ECR et GitHub Container Registry en ~4 heures.
Initial Access: Exploiting public-facing applications (e.g., React2Shell) and exposed APIs (Docker, Kubernetes, Redis, Ray dashboards).
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
Aikido Security - TeamPCP deploys CanisterWorm on NPM ... CanisterWorm — Self-propagating worm using ICP Canister for C2 ... File System Indicators /tmp/pglog (CanisterWorm payload drop path)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Utilisation des credentials volés pour compromettre des dizaines de packages npm via un ver auto-propagant nommé CanisterWorm.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions to the registry, expanding the attack surface.
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
It started with Aqua Security’s Trivy scanner and propagated downstream to multiple packages and repositories in a ripple effect fueled by the malware’s worm-like behavior and by the automated inclusion of the malicious libraries in more builds.
La campagne TeamPCP est une série d’attaques supply chain ciblant des outils open source largement utilisés dans les pipelines CI/CD. Des GitHub Actions, extensions OpenVSX et packages npm/PyPI ont été compromis et des versions malveillantes publiées.
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting...
They were injected with a .pth file that Python automatically executed at interpreter startup, even if LiteLLM was never imported, bypassing ignore-scripts protections.
Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions to the registry, expanding the attack surface.
Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions to the registry, expanding the attack surface.
CanisterWorm “harvested npm authentication tokens and attempted to spread itself by compromising additional packages.”
It also swept 50+ filesystem paths for SSH keys, AWS/GCP/Azure credentials, Kubernetes tokens, Docker configs, and cryptocurrency wallets.
"Long-lived credentials were found sitting in compromised repositories" and compromised packages searched environments for additional npm tokens.
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
One of the most striking aspects of the campaign was its extensive use of legitimate platforms for C2 and exfiltration. Rather than relying exclusively on traditional malware infrastructure, the attackers used GitHub repositories as dead-drop locations for stolen data.
Exfiltration chiffrée AES-256-GCM + RSA vers un endpoint imitant Checkmarx, avec dead-drop sur des dépôts GitHub aux noms thématiques Dune.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
120 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Self-propagating worm that used stolen credentials to compromise and publish malicious versions of more than 66 npm packages, extending the TeamPCP supply-chain attack chain.
Named only as part of a brokered data bundle; no malware functionality or direct operational relationship is described.
Credential-harvesting malware used to steal cloud access tokens, credentials, and API keys associated with AWS, GCP, and Azure.
TeamPCP npm worm spread through stolen publishing tokens, infecting packages rapidly, harvesting credentials, and self-propagating.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.