Rust-Written IronWorm Hits NPM Supply Chain
ID: 04824f32-5015-5537-bec3-96e3f6c235b4
STIX ID: report--04824f32-5015-5537-bec3-96e3f6c235b4
Feed Name: CosmicBytez Labs
Threat Score
**IronWorm** is a Rust-based supply-chain worm targeting the npm ecosystem that delivers cross-platform credential-stealing binaries via compromised maintainer accounts and typosquatted packages; stolen npm tokens, CI/CD secrets, and developer credentials are then reused to propagate the campaign, and organizations are advised to audit tokens, pin dependencies, monitor binary downloads, and review outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
