Dossier
IronWorm
Coverage of IronWorm in the Nexus archive.
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Multiple supply chain attacks targeted the npm ecosystem using malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm. JFrog identified the information stealer as hiding behind an eBPF kernel rootkit to scrape secrets from developers' machines.
- Rust-Written IronWorm Hits NPM Supply Chain
A Rust-written malware called IronWorm is targeting the NPM supply chain to steal developer credentials and reuse them for propagation. The campaign focuses on compromising software supply channels through credential theft.
- New IronWorm malware hits 36 packages in npm supply-chain attack
A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with infostealer malware called IronWorm.