CanisterWorm Hijacks 47 npm Packages Using ICP-Based C2
npm sits at the heart of JavaScript software distribution, so stolen publishing tokens can turn trusted maintainer accounts into a route into developer workstations and CI/CD pipelines. Aikido Security linked CanisterWorm to TeamPCP and the earlier compromise of Aqua Security’s Trivy scanner. The campaign is significant because it combines self-propagation with an Internet Computer Protocol, or ICP, canister used as a decentralized command-and-control dead drop, making the infrastructure harder to disable.
Aikido said it detected the campaign at 20:45 UTC on March 20, 2026, less than 24 hours after the Trivy attack, and counted 47 compromised npm packages: 28 under @EmilGroup, 16 under @opengov and three others. About an hour later, versions 1.8.11 and 1.8.12 of @teale.io/eslint-config added automated npm-token harvesting and worm propagation. The canister can redirect infected Linux hosts to new payload URLs, allowing TeamPCP to rotate malware without changing the implant.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.