SECURITYBLEEPING COMPUTER
New IronWorm malware hits 36 packages in npm supply-chain attack
A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm.
Mentioned
Related Signal
Adjacent reporting
- New Shai-Hulud malware wave compromises 600 npm packages
- Leaked Shai-Hulud malware fuels new npm infostealer campaign
- The never-ending supply chain attacks worm into SAP npm packages, other dev tools
- Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
- Another npm supply chain worm is tearing through dev environments
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm