logo

IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets

ID: c117c4d3-39f2-5a5c-a6de-3396d3f9a675

STIX ID: report--c117c4d3-39f2-5a5c-a6de-3396d3f9a675

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Tushar Subhra Dutta

...
...

IronWorm is a sophisticated supply-chain malware campaign targeting software developers via poisoned npm packages that silently execute a packed Rust infostealer. It uses an eBPF kernel-level rootkit to hide, communicates over Tor, exfiltrates a broad range of credentials (including crypto wallet recovery phrases and Kubernetes tokens), and self-propagates by using stolen GitHub credentials to create backdated commits and publish trojanized packages to npm; the report includes multiple IoCs and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.