Thehackernews CanisterWorm: New Self-Propagating Worm Targets NPM Packages Post-Trivy Attack
Article Content
- •CanisterWorm is a new self-propagating worm affecting NPM packages.
- •The attack is linked to TeamPCP, the same group behind the Trivy compromise.
- •Infected packages can harvest npm tokens, enabling further spread of the malware.
On March 20, 2026, a new worm named CanisterWorm was detected compromising numerous NPM packages, following a prior attack on the Trivy scanner. The threat actor, TeamPCP, is believed to be behind both attacks. CanisterWorm utilizes an ICP Canister for its command and control (C2) operations, marking a novel approach in malware deployment. The worm exploits npm tokens to self-propagate, significantly increasing its reach and impact. Initial payloads included a backdoor that installs a persistent service, while later versions introduced functionality to harvest npm tokens from compromised systems. The attack escalated from a single compromised account to a widespread infection vector, affecting developers and CI pipelines that use the targeted packages. Current status indicates ongoing risks as the worm continues to spread through infected packages. Security professionals are urged to monitor their systems for signs of infection.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CanisterWorm in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Armored Likho Expands Cyber-Espionage with New Rust Toolkit In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and educational institutions. The attackers employed a fraudulent donation-service application as the initial…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…