CanisterWorm is a self-propagating npm worm associated with the financially motivated threat actor TeamPCP, also tracked as UNC6780 and Altered Spider. Deployed in March 2026 using npm publishing tokens stolen during the Trivy supply-chain compromise, it spread through malicious releases of legitimate packages, affecting more than 60 npm packages across multiple publisher scopes. It targets developer environments, CI/CD systems, and Linux-based cloud infrastructure.
The worm searches compromised environments for npm authentication tokens, enumerates packages accessible through those tokens, and publishes infected versions to continue propagation. Malicious npm post-install scripts deploy a Python-based backdoor that establishes persistence through a systemd user service and masquerades as legitimate monitoring software. The backdoor periodically queries Internet Computer Protocol canister infrastructure to obtain locations for additional payloads, allowing operators to change follow-on code independently of published packages.
CanisterWorm harvests package-publishing credentials, cloud access tokens, and API keys, including authentication material for AWS, Google Cloud, and Azure. Its Python-based component SANDCLOCK targets Linux and Kubernetes environments and includes container-escape functionality and theft of developer credentials and cryptocurrency-wallet data. Follow-on payloads have extended propagation into Kubernetes and other infrastructure. The combination of credential theft, persistent remote execution, and automated package publication enables cascading compromises across software publishers and downstream users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
19 mars 2026 : Compromission de Trivy (scanner de vulnérabilités Aqua Security) via un tag malveillant v0.69.4 ( CVE-2026-33634 , CVSS v4 : 9.4). Propagation via GitHub Releases, Docker Hub, AWS ECR et GitHub Container Registry en ~4 heures.
Initial Access: Exploiting public-facing applications (e.g., React2Shell) and exposed APIs (Docker, Kubernetes, Redis, Ray dashboards).
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
Aikido Security - TeamPCP deploys CanisterWorm on NPM ... CanisterWorm — Self-propagating worm using ICP Canister for C2 ... File System Indicators /tmp/pglog (CanisterWorm payload drop path)
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A July FBI advisory (PDF) identified TeamPCP malware including CanisterWorm, SANDCLOCK, Mini Shai-Hulud and Miasma.
Google stated that SANDCLOCK is a component of what has publicly been referred to as CanisterWorm.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers used compromised tokens and GitHub credentials to replace CI scripts, trigger publishing workflows, create public repositories, and publish malicious updates through automated systems.
It started with Aqua Security’s Trivy scanner and propagated downstream to multiple packages and repositories in a ripple effect fueled by the malware’s worm-like behavior and by the automated inclusion of the malicious libraries in more builds.
La campagne TeamPCP est une série d’attaques supply chain ciblant des outils open source largement utilisés dans les pipelines CI/CD. Des GitHub Actions, extensions OpenVSX et packages npm/PyPI ont été compromis et des versions malveillantes publiées.
They were injected with a .pth file that Python automatically executed at interpreter startup, even if LiteLLM was never imported, bypassing ignore-scripts protections.
The S1ngularity script exfiltrated Nx's NPM token; Shai-Hulud and CanisterWorm searched victim machines for npm tokens to publish malicious versions of associated packages.
S1ngularity started by "pulling a token from the repository" and Shai-Hulud variants exploited long-lived credentials found in compromised repositories.
Post-install hooks scanned systems for "credentials, tokens, or SSH keys," while AI-agent prompts were intended to locate GitHub/NPM tokens, cloud credentials, and SSH keys.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
125 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TeamPCP-operated npm supply-chain worm that locates npm tokens on infected devices, identifies their associated packages, and overwrites those packages with malicious versions to continue propagation.
Malware described as spreading and wiping systems in Iran.
A worm reportedly used in TeamPCP's early attacks; the content provides no further technical capabilities.
A publicly used name for the broader malware activity or payload set of which SANDCLOCK is described as a component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.