BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

TeamPCP Worm Spreads to npm Via Blockchain C2

TeamPCP's CanisterWorm hijacks npm packages using blockchain-based decentralized command post.

  • Hackers linked to the TeamPCP operation have unleashed a self-propagating malware worm called CanisterWorm across numerous npm packages.
  • The worm uses an ICP canister on the Internet Computer blockchain as a resilient, decentralized command-and-control dead drop.
  • This attack is a follow-on to a previous supply chain compromise that published malicious versions of the popular Trivy security scanner.
  • Later worm variants automatically harvest npm authentication tokens from infected systems to propagate without any manual intervention from attackers.

A previously undocumented, self-propagating worm has compromised a large number of npm packages, according to research from Aikido Security. The malware, dubbed CanisterWorm by researcher Charlie Eriksen, marks the first documented abuse of an Internet Computer blockchain canister for cyber attacks.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

Consequently, infected packages leverage a postinstall hook to deploy a Python backdoor. This backdoor contacts a tamperproof ICP canister acting as a dead drop resolver to fetch its command server URL. The decentralized infrastructure makes takedown efforts highly resistant.

Eriksen noted, “The canister controller can swap the URL at any time, pushing new binaries to all infected hosts without touching the implant.” Persistence is achieved via a disguised systemd service, which masquerades as PostgreSQL tooling to avoid detection. The configuration uses a “Restart=always” directive to reactivate the backdoor automatically.

Meanwhile, the operation is suspected to be the work of the cloud-focused cybercriminal group TeamPCP. This development follows their prior attack where they used a compromised credential to publish malicious Trivy scanner releases containing a credential stealer. The worm’s initial propagation relied on a standalone “deploy.js” script run manually with stolen npm tokens.

However, a subsequent variant found in “@teale.io/eslint-config” versions 1.8.11 and 1.8.12 automated this process. The new version’s postinstall script hunts for npm tokens on the victim’s machine and uses them to self-propagate. Eriksen said, “This is the point where the attack goes from ‘compromised account publishes malware’ to ‘malware compromises more accounts and publishes itself.'”

- Advertisement -

Interestingly, the attacker has used a YouTube link as a kill switch within the canister, making the implant dormant. Currently, the canister returns a rickroll YouTube video, but the threat actor can arm it at any time using the canister’s “update_link” method. As of writing, this is a developing story with further details pending.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Mining Difficulty Plunges 7.7%

Bitcoin’s mining difficulty plunged 7.7% to 133.79 trillion on March 20, its sharpest decline...

Early Ethereum Whale Buys $19.5M ETH as Market Eyes Thaw

The wallet known as thomasg.eth purchased approximately $19.5 million in Ethereum over the past...

CISA Flags 5 Exploited Flaws in Apple, CMS

The U.S. CISA has added five actively exploited security flaws impacting Apple, Craft CMS,...

SHIB ETF Buzz Grows as T. Rowe Updates Crypto Fund Filing

T. Rowe has updated its ETF filing to include Shiba Inu (SHIB), signaling the...

Amid War, Bitcoin, Stocks Fall; Oil Soars 53%

Bitcoin fell nearly 5% recently amid a broad market decline, while crude oil saw...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading