CanisterWorm Malware Targets CI/CD Pipelines, Includes Iran-Focused Wiper
CanisterWorm: Open Source Compromise Escalates with Iran-Targeted Wiper
A self-propagating malware strain dubbed CanisterWorm is spreading through open-source software packages and has now been updated to include a wiper component specifically targeting systems in Iran. The malware, deployed by the threat actor TeamPCP, initially compromised CI/CD pipelines – the automated processes developers apply to build, test, and deploy software – and has demonstrated the potential for widespread disruption. The incident highlights the growing risks to the software supply chain and the increasing sophistication of attacks targeting cloud infrastructure.
The initial compromise, detected on March 20, 2026, involved the injection of malicious code into 28 packages within the @EmilGroup scope, 16 packages within the @opengov scope, and several individual packages including @teale.io/eslint-config, @airtm/uuid-base32, and @pypestream/floating-ui-dom. This was achieved using npm tokens harvested from a previous attack on the vulnerability scanner Trivy, as documented by Wiz and further detailed by Phoenix Security. TeamPCP’s five-day siege began with a single stolen GitHub token and cascaded across multiple platforms.
How CanisterWorm Works: A Three-Stage Attack
CanisterWorm employs a three-stage architecture. First, a Node.js postinstall loader is executed when a compromised package is installed. This loader then deploys a persistent Python backdoor on the affected system. Crucially, the malware utilizes an Internet Computer (ICP) canister – a decentralized storage and computation platform – as a command-and-control (C2) dead-drop. This innovative approach allows TeamPCP to dynamically deliver payloads and evade traditional takedown methods. According to Aikido Security researcher Charlie Eriksen, the use of an ICP canister for C2 is a first in this type of campaign.
The worm’s self-propagating nature is particularly concerning. The deploy.js script harvests npm tokens, resolves usernames, and enumerates all publishable packages. It then bumps the patch versions of these packages and publishes the malicious payload across the entire scope, potentially infecting numerous downstream users. Aikido Security observed the worm compromising 28 packages in under 60 seconds.
To ensure persistence, CanisterWorm installs a user-level service using systemd with a Restart=always directive. This ensures the malware survives reboots and automatically restarts if it crashes, all without requiring root privileges.
From Credential Stealer to Targeted Wiper
As the attack evolved, TeamPCP added a wiper payload, dubbed Kamikaze, specifically targeting machines in Iran. The updated worm checks the system’s timezone and language settings. If either matches Iran, the malware activates the wiper instead of the credential stealer. The wiper’s logic is straightforward, but destructive:
- Kubernetes + Iran: Deploys a DaemonSet to wipe every node in the cluster.
- Kubernetes + elsewhere: Deploys a DaemonSet to install the CanisterWorm backdoor on every node.
- No Kubernetes + Iran: Executes
rm -rf / --no-preserve-root, a command that recursively deletes all files on the system. - No Kubernetes + elsewhere: Does nothing.
While Eriksen reports no confirmed damage to Iranian machines as of March 20th, the potential for large-scale impact was significant. The simplicity and brutality of Kamikaze’s “decision tree” underscores the severity of the threat.
Motives and Implications
TeamPCP’s motivation for targeting Iran remains unclear. While the group has historically been financially motivated, the wiper attack appears to deviate from this pattern. Eriksen suggests the attack could be a deliberate attempt to gain attention, or a sign that visibility is becoming a goal in itself. “By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal,” Eriksen wrote.
The incident raises serious concerns about the security of the software supply chain. The compromise of Trivy, a vulnerability scanner, is particularly alarming, as it suggests that even security tools are not immune to attack. The cascading nature of the compromise – from Trivy to Checkmarx to npm – demonstrates how a single vulnerability can have far-reaching consequences. KrebsOnSecurity reports that TeamPCP has been compromising corporate cloud environments since December 2025, targeting exposed Docker APIs, Kubernetes clusters, and Redis servers.
The Role of the Internet Computer
The use of the Internet Computer (ICP) as a C2 infrastructure is a notable aspect of this attack. The ICP’s decentralized and censorship-resistant nature makes it tough to disrupt the malware’s communication channel. While the canister used by TeamPCP was taken down on Sunday night, Eriksen noted that it “wasn’t as reliable/untouchable as they expected,” suggesting that even decentralized infrastructure is not invulnerable.
Addressing the Vulnerabilities and What Comes Next
Aqua Security, the company behind Trivy, is conducting a more thorough credential purge in response to the compromise. Developers and organizations are advised to review their CI/CD pipelines, rotate npm tokens, and carefully vet all dependencies. Regularly scanning for vulnerabilities and implementing robust security practices are essential to mitigate the risk of supply chain attacks.
The incident also highlights the need for improved security measures within the npm ecosystem. While npm has implemented various security features, such as two-factor authentication and package integrity checks, these measures are not always sufficient to prevent sophisticated attacks. Further research and development are needed to enhance the security of open-source software and protect against evolving threats.
Looking ahead, security researchers will likely focus on analyzing the CanisterWorm malware in greater detail to understand its full capabilities and identify potential mitigation strategies. The incident serves as a stark reminder of the importance of proactive security measures and the need for collaboration between security researchers, software vendors, and the open-source community.