Cybersecurity & Privacy — 2026-03-23

TeamPCP Deploys 'CanisterWorm' Wiper via Trivy Supply Chain; Iran-Targeted Kubernetes Destruction

TeamPCP weaponized a supply chain compromise of Aqua Security's Trivy vulnerability scanner to deploy CanisterWorm, a self-propagating wiper targeting Iranian infrastructure. The malware uses timezone and locale checks (Asia/Tehran, fa_IR) to identify Iranian systems: on Kubernetes, a DaemonSet named 'host-provisioner-iran' deploys a 'kamikaze' container that wipes all host filesystems and force-reboots; non-K8s Iranian hosts receive 'rm -rf /'. Non-Iranian systems get a backdoor polling an ICP blockchain canister for C2. The attack compromised 75 of 76 trivy-action tags and expanded to 141 malicious package artifacts across Docker, npm, and GitHub registries.

Analysis
The Trivy supply chain compromise represents a novel convergence: cybercriminal infrastructure (TeamPCP has been active since December 2025) repurposed for geopolitically targeted destruction against Iranian systems. The blockchain-based C2 makes traditional takedown infeasible.
1 sources
  1. CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran - Aikido Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE