logo

IronWorm Campaign Targets Developers Through Malicious npm Packages

ID: e7e68b66-f463-5f00-aec7-b2b5d5f0104e

STIX ID: report--e7e68b66-f463-5f00-aec7-b2b5d5f0104e

Feed Name: Cyber Press

Threat Score
84/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Varshini

...
...

IronWorm is a sophisticated, active supply-chain malware campaign observed trojanizing npm packages using compromised GitHub accounts to target software developers—especially in the crypto and web3 sectors. The threat consists of a heavily obfuscated Rust infostealer bundled with a modified UPX packer and an eBPF kernel rootkit for stealth, harvests a wide range of credentials (environment variables, cloud/Kubernetes/AI API keys), uses forged/backdated commits and CI impersonation to propagate, and communicates via Tor-based C2. Multiple npm packages tied to the Arweave/WeaveDB ecosystem were republished from a compromised account, and the report provides package-version indicators and mitigation steps such as auditing repositories, rotating keys, and unpublishing suspicious npm versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.