logo

TeamPCP deploys CanisterWorm on NPM following Trivy compromise

ID: 4eb4ae5c-a51f-54b4-bf90-98074bdad6fc

STIX ID: report--4eb4ae5c-a51f-54b4-bf90-98074bdad6fc

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-03-20

Date Updated: 2026-07-24

...
...

On 2026-03-20 a self-propagating supply-chain campaign named "CanisterWorm" compromised dozens of npm packages by publishing malicious postinstall code that writes a Python backdoor (pgmon) as a user-level systemd service, uses an Internet Computer (ICP) canister as a decentralized C2 dead-drop to rotate payloads, and evolved to harvest npm authentication tokens to automatically spread across developer accounts and CI systems; the report includes technical breakdowns, sample code, IOC hashes, file paths, and C2 URLs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.