BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

TeamPCP Worm Spreads to npm Via Blockchain C2

TeamPCP's CanisterWorm hijacks npm packages using blockchain-based decentralized command post.

  • Hackers linked to the TeamPCP operation have unleashed a self-propagating malware worm called CanisterWorm across numerous npm packages.
  • The worm uses an ICP canister on the Internet Computer blockchain as a resilient, decentralized command-and-control dead drop.
  • This attack is a follow-on to a previous supply chain compromise that published malicious versions of the popular Trivy security scanner.
  • Later worm variants automatically harvest npm authentication tokens from infected systems to propagate without any manual intervention from attackers.

A previously undocumented, self-propagating worm has compromised a large number of npm packages, according to research from Aikido Security. The malware, dubbed CanisterWorm by researcher Charlie Eriksen, marks the first documented abuse of an Internet Computer blockchain canister for cyber attacks.

- Advertisement -

Consequently, infected packages leverage a postinstall hook to deploy a Python backdoor. This backdoor contacts a tamperproof ICP canister acting as a dead drop resolver to fetch its command server URL. The decentralized infrastructure makes takedown efforts highly resistant.

Eriksen noted, “The canister controller can swap the URL at any time, pushing new binaries to all infected hosts without touching the implant.” Persistence is achieved via a disguised systemd service, which masquerades as PostgreSQL tooling to avoid detection. The configuration uses a “Restart=always” directive to reactivate the backdoor automatically.

Meanwhile, the operation is suspected to be the work of the cloud-focused cybercriminal group TeamPCP. This development follows their prior attack where they used a compromised credential to publish malicious Trivy scanner releases containing a credential stealer. The worm’s initial propagation relied on a standalone “deploy.js” script run manually with stolen npm tokens.

However, a subsequent variant found in “@teale.io/eslint-config” versions 1.8.11 and 1.8.12 automated this process. The new version’s postinstall script hunts for npm tokens on the victim’s machine and uses them to self-propagate. Eriksen said, “This is the point where the attack goes from ‘compromised account publishes malware’ to ‘malware compromises more accounts and publishes itself.'”

- Advertisement -

Interestingly, the attacker has used a YouTube link as a kill switch within the canister, making the implant dormant. Currently, the canister returns a rickroll YouTube video, but the threat actor can arm it at any time using the canister’s “update_link” method. As of writing, this is a developing story with further details pending.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

US Crypto CLARITY Act Advances With Stablecoin Rule Text

The CLARITY Act, which aims to provide regulatory clarity for crypto, moves closer to...

Bitcoin Targets $80K As Data Signals Strong Buy Pressure

Bitcoin's price rebounded 2.52% to above $78,800 on Friday, holding support at its 100-day...

Google AppSheet Phishing Wave Hits 30K Facebook Accounts

Vietnamese threat actors used Google AppSheet as a phishing relay to compromise roughly 30,000...

Trump to hike EU auto tariffs to 25% from next week

Former US President Donald Trump announced via social media that tariffs on European Union...

Ethereum Foundation Sells $23M in ETH to BitMine

The Ethereum Foundation sold 10,000 ETH to BitMine Immersion Technologies for approximately $22.9 million.This...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading