CanisterWorm: New Self-Propagating Worm Targets NPM Packages Post-Trivy Attack

CanisterWorm: New Self-Propagating Worm Targets NPM Packages Post-Trivy Attack

First seen 21 Mar 2026, 08:41 UTC Aikido.DevThehackernewsItnews.AuGbhackersCybersecuritynews 78% similarity 69.6

Article Content

Browse articles
ThreatCluster

On March 20, 2026, a new worm named CanisterWorm was detected compromising numerous NPM packages, following a prior attack on the Trivy scanner. The threat actor, TeamPCP, is believed to be behind both attacks. CanisterWorm utilizes an ICP Canister for its command and control (C2) operations, marking a novel approach in malware deployment. The worm exploits npm tokens to self-propagate, significantly increasing its reach and impact. Initial payloads included a backdoor that installs a persistent service, while later versions introduced functionality to harvest npm tokens from compromised systems. The attack escalated from a single compromised account to a widespread infection vector, affecting developers and CI pipelines that use the targeted packages. Current status indicates ongoing risks as the worm continues to spread through infected packages. Security professionals are urged to monitor their systems for signs of infection.

Key Points: • CanisterWorm is a new self-propagating worm affecting NPM packages. • The attack is linked to TeamPCP, the same group behind the Trivy compromise. • Infected packages can harvest npm tokens, enabling further spread of the malware.

ThreatCluster AI

Timeline

2026-03-19
Trivy scanner compromise detected.
2026-03-20
CanisterWorm detected on NPM packages.
2026-03-20
Initial payloads identified with backdoor functionality.
2026-03-20
CanisterWorm updated to include self-propagation capabilities.

Community

Browse all →