IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Read full story on The Hacker News
Share
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
AI disclosure

Summary

Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the information stealer "scrapes every secret it can find on a developer's machine, hides behind an eBPF kernel rootkit, and

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.