CanisterWorm is a self-propagating npm worm deployed by the TeamPCP threat actor, discovered following the compromise of Trivy v0.69.4. Attackers embedded a credential harvester in Trivy's CI/CD toolchain, stole npm tokens from affected pipelines, then used those tokens to publish backdoored patch versions across multiple npm

9m read timeFrom stepsecurity.io
Post cover image
Table of contents
How We Detected ItThe Backstory: How CanisterWorm Gets InInside CanisterWorm: How It WorksIndicators of CompromiseWhat You Should DoHow StepSecurity HelpsReferences

Sort: