logo

Rust-Written IronWorm Hits NPM Supply Chain

ID: 6d6ac26c-a6b1-5130-bab2-8827e27c09e4

STIX ID: report--6d6ac26c-a6b1-5130-bab2-8827e27c09e4

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-06-04

Date Updated: 2026-06-15

Author: Jai Vijayan

...
...

IronWorm is a Rust-based malware campaign targeting developers and the open-source software supply chain: it steals API keys, cloud credentials, SSH keys and npm tokens, uses an eBPF rootkit to hide processes/files/network activity, communicates over Tor C2, and was found in at least 36 npm packages (≈32,000 monthly downloads) with multiple malicious commits before mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.