Thehackernews
CanisterWorm: New Self-Propagating Worm Targets NPM Packages Post-Trivy Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On March 20, 2026, a new worm named CanisterWorm was detected compromising numerous NPM packages, following a prior attack on the Trivy scanner. The threat actor, TeamPCP, is believed to be behind both attacks. CanisterWorm utilizes an ICP Canister for its command and control (C2) operations, marking a novel approach in malware deployment. The worm exploits npm tokens to self-propagate, significantly increasing its reach and impact. Initial payloads included a backdoor that installs a persistent service, while later versions introduced functionality to harvest npm tokens from compromised systems. The attack escalated from a single compromised account to a widespread infection vector, affecting developers and CI pipelines that use the targeted packages. Current status indicates ongoing risks as the worm continues to spread through infected packages. Security professionals are urged to monitor their systems for signs of infection.
Key Points: • CanisterWorm is a new self-propagating worm affecting NPM packages. • The attack is linked to TeamPCP, the same group behind the Trivy compromise. • Infected packages can harvest npm tokens, enabling further spread of the malware.