CanisterWorm — Malware Profile

CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns since at least 2026. CanisterWorm has used npm credentials to infect software packages and propagate across developer ecosystems. CanisterWorm has a targeted wiper component and can use decentralized C2 infrastructure implemented via an Internet Computer Protocol (ICP) blockchain canister.

MITRE ATT&CK techniques (32)

IntelFusions coverage

Attributed threat actors

Read the full analysis on IntelFusions