A new supply-chain attack named IronWorm has compromised 36 npm packages with infostealer malware written in Rust. The malware targets 86 environment variables and 20 credential files, seeking OpenAI, AWS, Anthropic, npm credentials, SSH keys, and cryptocurrency wallet files. It hides behind an eBPF kernel rootkit, communicates via Tor, and self-propagates by using stolen npm credentials to publish trojanized package versions. The attack originated from a compromised account 'asteroiddao' and uses backdated commits to evade investigation. A novel exfiltration mechanism abuses GitHub Actions build artifacts to deliver stolen secrets without needing a traditional C2 server. Researchers at JFrog, Ox Security, and Endor Labs detected the attack early before it spread to more popular packages. Developers are advised to upgrade to fixed releases, rotate credentials, and enable 2FA.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
178.5K Impressions21 Comments