logo

CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Alive

ID: 0718b035-b9cc-5613-95b8-954ebd9015c3

STIX ID: report--0718b035-b9cc-5613-95b8-954ebd9015c3

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-03-21

Date Updated: 2026-04-22

Author: Tom Abai

...
...

CanisterWorm is a self-propagating npm worm used by TeamPCP that steals npm tokens via malicious postinstall hooks (seeded by a prior Trivy supply-chain compromise), installs a persistent Python backdoor on Linux via a systemd user service, and retrieves payloads from an ICP canister C2; it then uses harvested tokens to publish patched malicious releases under victims' package names, enabling exponential spread and persistent control even after package takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.