New CanisterWorm Targets Kubernetes Clusters, Deploys “Kamikaze” Wiper
ID: 093ba2be-724e-5491-8005-c4779d635e47
STIX ID: report--093ba2be-724e-5491-8005-c4779d635e47
Feed Name: HackRead
CanisterWorm is a rapid supply-chain malware campaign attributed to 'TeamPCP' that has seeded malicious updates into dozens of npm packages using stolen credentials (linked to a compromise of Trivy). The malware steals authentication tokens and SSH keys to propagate, uses a blockchain-based Internet Computer Protocol canister as a resilient command-and-control channel, and exhibits destructive behavior—deploying a DaemonSet to push a 'Kamikaze' wiper across Kubernetes clusters in the Asia/Tehran timezone while installing backdoors elsewhere; developers should look for suspicious services named 'pgmon' or 'pgmonitor'.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
