CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive
ID: 0718b035-b9cc-5613-95b8-954ebd9015c3
STIX ID: report--0718b035-b9cc-5613-95b8-954ebd9015c3
Feed Name: Security Boulevard
Threat Score
CanisterWorm is a self-propagating npm worm used by TeamPCP that steals npm tokens via malicious postinstall hooks (seeded by a prior Trivy supply-chain compromise), installs a persistent Python backdoor on Linux via a systemd user service, and retrieves payloads from an ICP canister C2; it then uses harvested tokens to publish patched malicious releases under victims' package names, enabling exponential spread and persistent control even after package takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
