CanisterWorm is a self-spreading npm worm discovered on March 20, 2026, deployed by threat actor group TeamPCP. It originated from stolen npm tokens harvested via a compromised Trivy GitHub Actions workflow. Once a developer installs an infected package, a postinstall hook steals npm tokens, installs a persistent Python

11m read timeFrom securityboulevard.com
Post cover image
Table of contents
Background: How TeamPCP Got the KeysTechnical Analysis of the CanisterWormImpact AnalysisIndicators of CompromiseDetection and RemediationAttributionConclusion

Sort: