LIVE NEWS
  • The lamentable state of British defence acquisition
  • One of the sky’s rarest phenomena is back — How to see rare night-shining clouds this summer
  • A maritime drone explodes at a Romanian Black Sea port, no one hurt
  • A stablecoin tied to Strategy stock depegs putting a new DeFi dollar risk in focus as Bitcoin sells off
  • Rust-Written IronWorm Hits NPM Supply Chain
  • Panini stickers, a World Cup tradition, sees biggest demand yet in the U.S. : NPR
  • As Global Demand for Gold Grows, UN Mercury Head Warns Toxic Fumes Put Women in a Motherhood Dilemma — Global Issues
  • XAU/USD languishes below $4,480 with US Nonfarn Payrolls on tap
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Rust-Written IronWorm Hits NPM Supply Chain
Cybersecurity

Rust-Written IronWorm Hits NPM Supply Chain

primereportsBy primereportsJune 5, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Rust-Written IronWorm Hits NPM Supply Chain
Share
Facebook Twitter LinkedIn Pinterest Email


A newly discovered malware campaign targeting the open source software ecosystem underscores how rapidly supply chain threats are evolving. 

The campaign, which JFrog has dubbed “IronWorm,” targets developers through compromised npm publishing workflows and malicious package updates. The malware, written in Rust, harvests a wide range of developer secrets, including API keys, cloud credentials, SSH keys, and npm publishing tokens, and reuses them to spread further across the software supply chain.

Similar to the Shai-Hulud Campaign

JFrog identified the activity while investigating suspicious behavior linked to a developer account within the Arweave/WeaveDB open source ecosystem. 

IronWorm’s payload shares architectural similarities with last year’s Shai-Hulud worm and features a unique combination of mechanisms for credential theft, persistence, and covert Tor-based command-and-control communications (C2), JFrog said.

Related:Pakistan Spies on Afghan Finance Ministry With Xeno RAT

The security vendor’s analysis showed IronWorm uses a rootkit that abuses the Linux kernel’s extended Berkeley Packet Filter(eBPF) to hide malicious processes, files, network activity, and other behavior from security systems. It also encrypts embedded text using unique encryption keys throughout the codebase rather than a single hardcoded key, making the malware significantly harder to analyze and detect, JFrog said.

Researchers at OX Security also tracking the campaign described it as having affected at least 36 unique npm packages with more 32,000 combined monthly downloads. The company said the threat was mitigated before it could spread to other, more popular packages. 

In its report, JFrog itself described the operator of the IronWorm campaign as having deprecated the malicious packages, silently removing them from GitHub within a day of publishing them to the repository. However, by then the threat actor appeared to have made at least 57 malicious code changes to repositories belonging to nine organizations, the security vendor added. The attacker backdated the changes in an attempt to obscure the timeline of compromise and to complicate forensic analysis, JFrog noted.

IronWorm: A Unique Piece of Malware?

“We checked the sample against every well-known infostealer, eBPF rootkit, and C2 framework we could think of, and matched none of them,” JFrog said. “There are no source-repository URLs in the binary, no borrowed code we could recognize.” JFrog concluded that the IronWorm payload with its combination of features and encryption is a “custom, carefully built implant” that someone is using in a sophisticated and painstaking operation.

Related:Tropical Blend: Cyber & Politics Ramp Up Across Latin America

“The closest comparison is the Shai-Hulud campaign,” JFrog said. The malware we reviewed shares a lot with it: the same idea of compromising developers, stealing credentials, and using trusted software-supply-chain workflows to spread further, using the same commit names as Shai Hulud does. But it takes the same concept to the next level.”

IronWorm is the latest indication of how developers and development environments have become prime targets for threat actors looking to compromise supply chains. Driving the interest is the fact that developers often hold privileged access to source code repositories, package registries, cloud environments, CI/CD pipelines, and signing keys. By compromising a single developer, threat actors can potentially introduce malicious code into trusted software projects and reach numerous downstream organizations and users. 

Such attacks have unfolded in multiple ways. Earlier this year for example, a threat actor pushed malicious commits to more than 5,500 GitHub repositories in a matter of hours using a credential stealing malware payload dubbed Megalodon. In other campaigns, the TeamPCP cybercrime group compromised Trivy, a popular cloud security scanning tool, as well as other projects to deploy infostealers targeting cloud credentials, tokens, SSH keys and other secrets from CI/CD workflows. In 2024, attackers used a combination of stolen code, weaponized commits and a counterfeit Python package source to hijack GitHub accounts.

Related:Global Stock Exchange Hit by Monthslong Email Campaign



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePanini stickers, a World Cup tradition, sees biggest demand yet in the U.S. : NPR
Next Article A stablecoin tied to Strategy stock depegs putting a new DeFi dollar risk in focus as Bitcoin sells off
primereports
  • Website

Related Posts

Cybersecurity

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

June 4, 2026
Cybersecurity

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security

June 4, 2026
Cybersecurity

Chinese Cybercrime Group in Spotlight for Record Campaign Pace

June 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • The lamentable state of British defence acquisition
  • One of the sky’s rarest phenomena is back — How to see rare night-shining clouds this summer
  • A maritime drone explodes at a Romanian Black Sea port, no one hurt
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.