BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

TeamPCP Worm Spreads to npm Via Blockchain C2

TeamPCP's CanisterWorm hijacks npm packages using blockchain-based decentralized command post.

  • Hackers linked to the TeamPCP operation have unleashed a self-propagating malware worm called CanisterWorm across numerous npm packages.
  • The worm uses an ICP canister on the Internet Computer blockchain as a resilient, decentralized command-and-control dead drop.
  • This attack is a follow-on to a previous supply chain compromise that published malicious versions of the popular Trivy security scanner.
  • Later worm variants automatically harvest npm authentication tokens from infected systems to propagate without any manual intervention from attackers.

A previously undocumented, self-propagating worm has compromised a large number of npm packages, according to research from Aikido Security. The malware, dubbed CanisterWorm by researcher Charlie Eriksen, marks the first documented abuse of an Internet Computer blockchain canister for cyber attacks.

- Advertisement -

Consequently, infected packages leverage a postinstall hook to deploy a Python backdoor. This backdoor contacts a tamperproof ICP canister acting as a dead drop resolver to fetch its command server URL. The decentralized infrastructure makes takedown efforts highly resistant.

Eriksen noted, “The canister controller can swap the URL at any time, pushing new binaries to all infected hosts without touching the implant.” Persistence is achieved via a disguised systemd service, which masquerades as PostgreSQL tooling to avoid detection. The configuration uses a “Restart=always” directive to reactivate the backdoor automatically.

Meanwhile, the operation is suspected to be the work of the cloud-focused cybercriminal group TeamPCP. This development follows their prior attack where they used a compromised credential to publish malicious Trivy scanner releases containing a credential stealer. The worm’s initial propagation relied on a standalone “deploy.js” script run manually with stolen npm tokens.

However, a subsequent variant found in “@teale.io/eslint-config” versions 1.8.11 and 1.8.12 automated this process. The new version’s postinstall script hunts for npm tokens on the victim’s machine and uses them to self-propagate. Eriksen said, “This is the point where the attack goes from ‘compromised account publishes malware’ to ‘malware compromises more accounts and publishes itself.'”

- Advertisement -

Interestingly, the attacker has used a YouTube link as a kill switch within the canister, making the implant dormant. Currently, the canister returns a rickroll YouTube video, but the threat actor can arm it at any time using the canister’s “update_link” method. As of writing, this is a developing story with further details pending.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Salesforce ties Anthropic bet, Slack AI to counter SaaS threat

Salesforce CEO Marc Benioff stated Microsoft’s OpenAI ties blocked Salesforce from investing, leading to...

UN Security Council to Hear AI CEOs on Risks Before Trump-Xi Meet

Anthropic, OpenAI, DeepSeek, and Moonshot will brief the UN Security Council on AI risks...

OpenAI launches cheaper GPT-6 Sol and Luna for coding and work tasks

OpenAI launched GPT-6 Sol at $2 per million input tokens and $10 per million...

Kalshi bot stops uniform trades amid wash trade claims

A trading bot repeatedly buying and selling $1 contracts on Kalshi's Zohran Mamdani prediction...

Six Canadian banks explore tokenized CAD deposits

Canada’s six largest banks jointly explore tokenized Canadian dollar deposits to enable digital bank...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading