
The individuals responsible for the supply chain attack on the Trivy scanner are believed to be launching additional attacks, compromising numerous npm packages with a novel self-spreading worm named CanisterWorm.
The name comes from the malware’s usage of an ICP canister, a secure smart contract on the Internet Computer blockchain, as a dead drop resolver. According to Aikido Security researcher Charlie Eriksen, this is the first known instance of an ICP canister being used to obtain the command-and-control (C2) server. He stated that TeamPCP is behind this.
The following is a list of the compromised packages:
This occurs shortly after attackers used a compromised account to release malicious versions of trivy, trivy-action, and setup-trivy. These versions contained a tool to steal credentials. TeamPCP, a cybercriminal group focused on cloud services, is suspected of orchestrating these attacks.
The attack sequence affecting the npm packages involves using a postinstall hook to run a loader. This loader then installs a Python backdoor. The backdoor gets a URL for the next stage of the attack from the ICP canister. The decentralized nature of the dead drop infrastructure makes it difficult to shut down and more resilient.
“The canister controller can change the URL whenever they want, and push new files to all infected devices without touching the implant,” Eriksen explained.
Persistence is achieved through a systemd user service that automatically restarts the Python backdoor after a short delay if it is stopped, using the “Restart=always” directive. The systemd service pretends to be PostgreSQL tooling (“pgmon”) as a disguise.
As previously mentioned, the backdoor contacts the ICP canister every 50 minutes using a fake browser User-Agent to retrieve the URL in plain text. This URL is then used to download and run the executable.
“If the URL contains youtube[.]com, the script doesn’t use it,” Eriksen said. “That means the canister is dormant. The attacker activates the implant by setting the canister to a real file address and deactivates it by switching back to a YouTube link. When the attacker updates the canister to point to a new URL, all infected devices download the new binary the next time they check. The old binary continues to run because the script never closes existing processes.”
Wiz has also identified that a similar kill switch using youtube[.]com was also incorporated into the compromised Trivy binary (version 0.69.4), which uses the same ICP canister via a Python dropper (“sysmon.py”). Currently, the URL provided by the C2 is a Rickroll YouTube video.
The Hacker News determined that the ICP canister offers three functions â get_latest_link, http_request, update_link â which allows the attacker to modify its behavior and deliver a real payload at any time.
Additionally, the packages contain a “deploy.js” file. The attacker uses this to automatically distribute the malicious code to every package a stolen npm token grants access to. The worm, likely created with AI, makes no attempt to hide what it does.
“This isn’t triggered by npm install,” Aikido stated. “The attacker runs it as a standalone tool using stolen tokens to spread the damage as much as possible.”
To make matters worse, a later version of CanisterWorm, found in “@teale.io/eslint-config” versions 1.8.11 and 1.8.12, has been observed to spread itself without requiring any manual steps.
Unlike “deploy.js,” a separate script that the attacker needed to run with stolen npm tokens to send a malicious version of the npm packages to it’s registry, the updated variant includes this functionality in “index.js” within a findNpmTokens() function that runs during the postinstall process to obtain user npm authentication tokens from the compromised device.
The main change here is that the postinstall script, after installing the persistent backdoor, tries to find any npm tokens from the developer’s system. It then launches “deploy.js” as a completely separate background process, beginning the worm with the stolen tokens.
Interestingly, it seems the attacker initially swapped out the ICP backdoor payload for a placeholder string (“hello123”). This was likely to confirm that the entire attack chain was working prior to deploying malware.
“Now the attack becomes one where ‘a compromised account publishes malware’ becomes ‘malware compromises more accounts and publishes itself,'” Eriksen explained. “Any developer or CI/CD pipeline that installs this package and has an accessible npm token will unknowingly spread it. Their packages become infected, their end-users install those and if any of *them* have tokens, the cycle restarts.”
(This story is still developing. Please check back for updates.)
#canisterworm #flaw #infects #news #npm #packages #rapidly. #sparks #spreads #trivy #worm — News
© Bulletproof Servers. All rights reserved.