Cybersecurity & Privacy — 2026-03-23
Trivy Supply Chain Attack Spawns CanisterWorm Wiper Targeting Iranian Systems
The compromise of Aqua Security's Trivy vulnerability scanner has escalated dramatically. Threat group TeamPCP hijacked 75 of 76 version tags in the trivy-action GitHub repository, distributing an infostealer through CI/CD pipelines. The attack then spawned CanisterWorm — a self-propagating worm targeting Docker, Kubernetes, and Redis infrastructure that deploys a wiper specifically against systems in Iran's timezone or with Farsi language settings. TeamPCP coordinates operations through tamperproof ICP blockchain canisters resistant to takedown. The wiper represents a cybercrime group attempting to inject itself into the Iran war by targeting Iranian infrastructure.
3 sources
- 'CanisterWorm' Springs Wiper Attack Targeting Iran -
Krebs on Security - Trivy supply-chain attack spreads to Docker, GitHub repos -
BleepingComputer - Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes Wiper -
The Hacker News