Rust-Written IronWorm Hits NPM Supply Chain
ID: 6d6ac26c-a6b1-5130-bab2-8827e27c09e4
STIX ID: report--6d6ac26c-a6b1-5130-bab2-8827e27c09e4
Feed Name: Dark Reading
Threat Score
IronWorm is a Rust-based malware campaign targeting developers and the open-source software supply chain: it steals API keys, cloud credentials, SSH keys and npm tokens, uses an eBPF rootkit to hide processes/files/network activity, communicates over Tor C2, and was found in at least 36 npm packages (≈32,000 monthly downloads) with multiple malicious commits before mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
