MAL-2026-2213

    Dashboard / Malicious Package / MAL-2026-2213

    MAL-2026-2213

    Published: 26 Mar 2026Last Modified: 31 Mar 2026

    Summary: Malicious code in @virtahealth/substrate-root (npm)

    Details: Source: amazon-inspector (c8348bbc19210fd9962510b31c4e08572ba739767bd183a4c867071a9a5f9d18) The package @virtahealth/substrate-root was found to contain malicious code. Source: google-open-source-security (010efef42ba2d9d54d09099af01e1bf536eedbdb4f873b02785f625a258d3801) This package was compromised by the CanisterWorm campaign by the TeamPCP threat actor. The malicious payload establishes persistence as user systemd service and places a backdoor on the infected host. The malware will also harvest npm credentials and can autonomously spread.

    Affected packages

    Package

    Name: @virtahealth/substrate-root

    Purl: pkg:npm/%40virtahealth/substrate-root

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    MAL-2026-2213 | CVE-DB