TeamPCP deploys CanisterWorm on NPM following Trivy compromise
ID: 4eb4ae5c-a51f-54b4-bf90-98074bdad6fc
STIX ID: report--4eb4ae5c-a51f-54b4-bf90-98074bdad6fc
Feed Name: Aikido Security's Blog
On 2026-03-20 a self-propagating supply-chain campaign named "CanisterWorm" compromised dozens of npm packages by publishing malicious postinstall code that writes a Python backdoor (pgmon) as a user-level systemd service, uses an Internet Computer (ICP) canister as a decentralized C2 dead-drop to rotate payloads, and evolved to harvest npm authentication tokens to automatically spread across developer accounts and CI systems; the report includes technical breakdowns, sample code, IOC hashes, file paths, and C2 URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
