CanisterWorm
MITRE ATT&CK: S9042 View on attack.mitre.org
Aliases: CanisterWorm
- Profile updated
- 2026-08-15 03:00:05
Context
CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns since at least 2026. CanisterWorm has used npm credentials to infect software packages and propagate across developer ecosystems. CanisterWorm has a targeted wiper component and can use decentralized C2 infrastructure implemented via an Internet Computer Protocol (ICP) blockchain canister.(Citation: Aikido TeamPCP Telnyx MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Aikido CanisterWorm MAR 2026)(Citation: Aikido TeamPCP Trivy MAR 2026)
Used by threat actors
- TeamPCP (threat-actor)
Reports & references
- Palo Alto Unit 42 — Teampcp Supply Chain Attacks (report)
- MITRE ATT&CK — S9042 (report)
- aikido.dev — Teampcp Deploys Worm Npm Trivy Compromise (report)
- aikido.dev — Teampcp Stage Payload Canisterworm Iran (report)
- aikido.dev — Telnyx Pypi Compromised Teampcp Canisterworm (report)