logo

New CanisterWorm Targets Kubernetes Clusters, Deploys “Kamikaze” Wiper

ID: 093ba2be-724e-5491-8005-c4779d635e47

STIX ID: report--093ba2be-724e-5491-8005-c4779d635e47

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

CanisterWorm is a rapid supply-chain malware campaign attributed to 'TeamPCP' that has seeded malicious updates into dozens of npm packages using stolen credentials (linked to a compromise of Trivy). The malware steals authentication tokens and SSH keys to propagate, uses a blockchain-based Internet Computer Protocol canister as a resilient command-and-control channel, and exhibits destructive behavior—deploying a DaemonSet to push a 'Kamikaze' wiper across Kubernetes clusters in the Asia/Tehran timezone while installing backdoors elsewhere; developers should look for suspicious services named 'pgmon' or 'pgmonitor'.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.