Skip to content
The Nexus
SECURITYJun 5 · 18:05 UTCTHE HACKER NEWS[email protected] (The Hacker News)

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Multiple supply chain attacks targeted the npm ecosystem using malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm. JFrog identified the information stealer as hiding behind an eBPF kernel rootkit to scrape secrets from developers' machines.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this