IronWorm malware infects 36 npm packages with Rust-based infostealer. It targets 86 environment variables and 20 credential files including OpenAI, AWS, Anthropic, npm, SSH keys, and Exodus wallet files. The malware hides behind an eBPF kernel rootkit and communicates via Tor. Researchers at JFrog identified the attack in npm supply-chain.
Tap to vote and see what everyone thinks.
Red Hat npm packages compromised to steal developer credentials
Summary by ByteBrief