ATT&CKSoftwareCanisterWorm

CanisterWorm

S9042

Malware.View on attack.mitre.org

About this malware

CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns since at least 2026. CanisterWorm has used npm credentials to infect software packages and propagate across developer ecosystems. CanisterWorm has a targeted wiper component and can use decentralized C2 infrastructure implemented via an Internet Computer Protocol (ICP) blockchain canister.

Techniques used32

Procedure examples32

TechniqueProcedure example
T1016
System Network Configuration Discovery

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.

T1018
Remote System Discovery

CanisterWorm has scanned the local /24 subnet for new targets.

T1027.009
Embedded Payloads

CanisterWorm has used embedded second stage Base64-encoded payloads.

T1033
System Owner/User Discovery

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames.

T1036.004
Masquerade Task or Service

CanisterWorm has masqueraded itself as systemd or as a PostgreSQL utility named pgmon.

T1036.005
Match Legitimate Resource Name or Location

CanisterWorm has mimicked legitimate PostgreSQL components (pgmon, pglog, and .pg_state) to masquerade malicious files.

T1053.006
Systemd Timers

CanisterWorm has registered itself as a systemd service for persistence on targeted Kubernetes nodes.

T1059.004
Unix Shell

CanisterWorm has used shell commands to enable and start the malicious systemd service for execution and persistence.

T1059.006
Python

CanisterWorm has used a Python script as a second-stage backdoor.

T1059.007
JavaScript

CanisterWorm can leverage stolen tokens to execute Javascsript (deploy.js) for self-propagation.

T1070.004
File Deletion

CanisterWorm has deleted itself after execution.

T1083
File and Directory Discovery

CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values.

T1102.001
Dead Drop Resolver

CanisterWorm can periodically poll a decentralized Internet Computer Protocol (ICP) canister to retrieve a dynamic URL for payload delivery.

T1105
Ingress Tool Transfer

CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed.

T1124
System Time Discovery

CanisterWorm has checked if the target system’s time zone is “Asia/Tehran” or “Iran.”

View all 32 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. Aikido CanisterWorm MAR 2026 Open source
    Eriksen, C. (2026, March 22). CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran. Retrieved July 27, 2026.
  2. Aikido TeamPCP Telnyx MAR 2026 Open source
    Eriksen, C. (2026, March 27). Popular telnyx package compromised on PyPI by TeamPCP. Retrieved July 16, 2026.
  3. Aikido TeamPCP Trivy MAR 2026 Open source
    Eriksen, C. (2026, March 20). TeamPCP deploys CanisterWorm on NPM following Trivy compromise. Retrieved July 27, 2026.
  4. Palo Alto TeamPCP MAR 2026 Open source
    Unit 42. (2026, March 31). Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure. Retrieved July 1, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.