IronWorm malware compromises 36 npm packages in supply-chain attack (bleepingcomputer.com)
0xBASE INTEL BRIEF
- 36 npm packages infected with IronWorm
- Rust-based, eBPF rootkit, Tor communication
- Targets OpenAI, AWS, and npm credentials
"A new supply-chain attack has infected 36 packages on the Node Package Manager (npm) index with the IronWorm infostealer malware. The Rust-based malware uses an eBPF kernel rootkit, communicates over Tor, and targets 86 environment variables and 20 credential files, including OpenAI, AWS, and npm credentials. It self-propagates using stolen npm publishing credentials."
no comments yet.