CanisterWorm is a self-propagating npm worm deployed by the TeamPCP threat actor, discovered following the compromise of Trivy v0.69.4. Attackers embedded a credential harvester in Trivy's CI/CD toolchain, stole npm tokens from affected pipelines, then used those tokens to publish backdoored patch versions across multiple npm
Table of contents
How We Detected ItThe Backstory: How CanisterWorm Gets InInside CanisterWorm: How It WorksIndicators of CompromiseWhat You Should DoHow StepSecurity HelpsReferencesSort: