Skip to main content
List Directory
  • News
  • World
  • Business
  • Entertainment
  • Sports
  • Tech and Science
  • Health
Menu
  • News
  • World
  • Business
  • Entertainment
  • Sports
  • Tech and Science
  • Health

CanisterWorm Malware Targets CI/CD Pipelines, Includes Iran-Focused Wiper

March 25, 2026 Sarah Wu - Tech Editor Tech and Science

CanisterWorm: Open Source Compromise Escalates with Iran-Targeted Wiper

A self-propagating malware strain dubbed CanisterWorm is spreading through open-source software packages and has now been updated to include a wiper component specifically targeting systems in Iran. The malware, deployed by the threat actor TeamPCP, initially compromised CI/CD pipelines – the automated processes developers apply to build, test, and deploy software – and has demonstrated the potential for widespread disruption. The incident highlights the growing risks to the software supply chain and the increasing sophistication of attacks targeting cloud infrastructure.

The initial compromise, detected on March 20, 2026, involved the injection of malicious code into 28 packages within the @EmilGroup scope, 16 packages within the @opengov scope, and several individual packages including @teale.io/eslint-config, @airtm/uuid-base32, and @pypestream/floating-ui-dom. This was achieved using npm tokens harvested from a previous attack on the vulnerability scanner Trivy, as documented by Wiz and further detailed by Phoenix Security. TeamPCP’s five-day siege began with a single stolen GitHub token and cascaded across multiple platforms.

How CanisterWorm Works: A Three-Stage Attack

CanisterWorm employs a three-stage architecture. First, a Node.js postinstall loader is executed when a compromised package is installed. This loader then deploys a persistent Python backdoor on the affected system. Crucially, the malware utilizes an Internet Computer (ICP) canister – a decentralized storage and computation platform – as a command-and-control (C2) dead-drop. This innovative approach allows TeamPCP to dynamically deliver payloads and evade traditional takedown methods. According to Aikido Security researcher Charlie Eriksen, the use of an ICP canister for C2 is a first in this type of campaign.

The worm’s self-propagating nature is particularly concerning. The deploy.js script harvests npm tokens, resolves usernames, and enumerates all publishable packages. It then bumps the patch versions of these packages and publishes the malicious payload across the entire scope, potentially infecting numerous downstream users. Aikido Security observed the worm compromising 28 packages in under 60 seconds.

To ensure persistence, CanisterWorm installs a user-level service using systemd with a Restart=always directive. This ensures the malware survives reboots and automatically restarts if it crashes, all without requiring root privileges.

From Credential Stealer to Targeted Wiper

As the attack evolved, TeamPCP added a wiper payload, dubbed Kamikaze, specifically targeting machines in Iran. The updated worm checks the system’s timezone and language settings. If either matches Iran, the malware activates the wiper instead of the credential stealer. The wiper’s logic is straightforward, but destructive:

  • Kubernetes + Iran: Deploys a DaemonSet to wipe every node in the cluster.
  • Kubernetes + elsewhere: Deploys a DaemonSet to install the CanisterWorm backdoor on every node.
  • No Kubernetes + Iran: Executes rm -rf / --no-preserve-root, a command that recursively deletes all files on the system.
  • No Kubernetes + elsewhere: Does nothing.

While Eriksen reports no confirmed damage to Iranian machines as of March 20th, the potential for large-scale impact was significant. The simplicity and brutality of Kamikaze’s “decision tree” underscores the severity of the threat.

Motives and Implications

TeamPCP’s motivation for targeting Iran remains unclear. While the group has historically been financially motivated, the wiper attack appears to deviate from this pattern. Eriksen suggests the attack could be a deliberate attempt to gain attention, or a sign that visibility is becoming a goal in itself. “By going after security tools and open-source projects, including Checkmarx as of today, they are sending a clear and deliberate signal,” Eriksen wrote.

The incident raises serious concerns about the security of the software supply chain. The compromise of Trivy, a vulnerability scanner, is particularly alarming, as it suggests that even security tools are not immune to attack. The cascading nature of the compromise – from Trivy to Checkmarx to npm – demonstrates how a single vulnerability can have far-reaching consequences. KrebsOnSecurity reports that TeamPCP has been compromising corporate cloud environments since December 2025, targeting exposed Docker APIs, Kubernetes clusters, and Redis servers.

The Role of the Internet Computer

The use of the Internet Computer (ICP) as a C2 infrastructure is a notable aspect of this attack. The ICP’s decentralized and censorship-resistant nature makes it tough to disrupt the malware’s communication channel. While the canister used by TeamPCP was taken down on Sunday night, Eriksen noted that it “wasn’t as reliable/untouchable as they expected,” suggesting that even decentralized infrastructure is not invulnerable.

Addressing the Vulnerabilities and What Comes Next

Aqua Security, the company behind Trivy, is conducting a more thorough credential purge in response to the compromise. Developers and organizations are advised to review their CI/CD pipelines, rotate npm tokens, and carefully vet all dependencies. Regularly scanning for vulnerabilities and implementing robust security practices are essential to mitigate the risk of supply chain attacks.

The incident also highlights the need for improved security measures within the npm ecosystem. While npm has implemented various security features, such as two-factor authentication and package integrity checks, these measures are not always sufficient to prevent sophisticated attacks. Further research and development are needed to enhance the security of open-source software and protect against evolving threats.

Looking ahead, security researchers will likely focus on analyzing the CanisterWorm malware in greater detail to understand its full capabilities and identify potential mitigation strategies. The incident serves as a stark reminder of the importance of proactive security measures and the need for collaboration between security researchers, software vendors, and the open-source community.

Recent Posts

  • Madison Keys vs. Hanne Vandewinkel Live: French Open 2026 TV Schedule and Streaming Guide
  • Our Strict Quality Control Process for Returned Clothing
  • German Business Sentiment Shows Slight Recovery in May According to Ifo Index
  • The 2-week supplement to avoid travel tummy trouble – plus blood clots worries – The Irish Sun
  • Ukraine Achieves Major Battlefield Successes as Russian Casualties Mount

Recent Comments

No comments to show.
List Directory

List-Directory is a comprehensive directory of businesses and services across the United States. Find what you need, when you need it.

Quick Links

  • Home
  • Privacy Policy
  • Terms of Service

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

Connect With Us

Official social links will appear here when available.

List-directory.com
For contact, advertising, copyright, issues email: office@list-directory.com

Privacy Policy Terms of Service