SECURITYDARK READING
Rust-Written IronWorm Hits NPM Supply Chain
A Rust-written malware called IronWorm is targeting the NPM supply chain to steal developer credentials and reuse them for propagation. The campaign focuses on compromising software supply channels through credential theft.
Related Signal
Adjacent reporting
- Shai-Hulud: What to Know About the Malware Spreading Through Software Pipelines
- Laravel Lang packages hijacked to deploy credential-stealing malware
- ‘TrapDoor’ malware targets crypto dev tools in supply chain attack
- Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise
- DPRK Fake Job Scams Self-Propagate in 'Contagious Interview'
- Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft