Eriksen, C. (2026, March 20). TeamPCP deploys CanisterWorm on NPM following Trivy compromise. Retrieved July 27, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
MalwareCanisterWorm | CanisterWorm has used embedded second stage Base64-encoded payloads. |
| T1036.004 Masquerade Task or Service |
MalwareCanisterWorm | CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCanisterWorm | CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files. |
| T1053.006 Systemd Timers |
MalwareCanisterWorm | CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes. |
| T1059.004 Unix Shell |
MalwareCanisterWorm | CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence. |
| T1059.006 Python |
MalwareCanisterWorm | CanisterWorm has used a Python script as a second-stage backdoor. |
| T1059.007 JavaScript |
MalwareCanisterWorm | CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation. |
| T1083 File and Directory Discovery |
MalwareCanisterWorm | CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values. |
| T1102.001 Dead Drop Resolver |
MalwareCanisterWorm | CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery. |
| T1105 Ingress Tool Transfer |
MalwareCanisterWorm | CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCanisterWorm | CanisterWorm has decoded a long Base64 string to obtain a Python script for its second-stage payload. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareCanisterWorm | CanisterWorm has spread through an automated process that infects and publishes npm packages. |
| T1497.003 Time Based Checks |
MalwareCanisterWorm | CanisterWorm has leveraged a Sleep setting of five minutes before executing tasks to evade sandbox environments. |
| T1543 Create or Modify System Process |
MalwareCanisterWorm | CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens. |
| T1550.001 Application Access Token |
MalwareCanisterWorm | CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope. |
| T1569.003 Systemctl |
MalwareCanisterWorm | CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service. |
| T1677 Poisoned Pipeline Execution |
MalwareCanisterWorm | CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.