Last updated 1 month ago
The NPM software supply chain was targeted by a Rust-written malware campaign named IronWorm, disclosed in June 2026. The campaign specifically targets developers to steal their credentials, which are then reused to propagate across the software supply chain. The full scope of affected packages and users has not been quantified.
The attack vector is a supply chain compromise via malicious packages uploaded to the NPM registry. The malware, written in Rust, is designed to harvest developer credentials and reuse them to spread further within the supply chain. No specific threat actor has been attributed, and no CVEs or MITRE ATT&CK techniques were cited in the article.
No post-incident developments such as regulatory actions, litigation, ransom payments, or containment milestones were reported.
Malicious Rust-written package (IronWorm) uploaded to NPM registry, targeting developers to steal credentials and propagate across the software supply chain.
The IronWorm campaign against NPM highlights the critical need for robust package integrity verification and credential hygiene in software supply chains. Organizations relying on NPM packages must implement automated scanning for malicious code, enforce multi-factor authentication for developer accounts, and monitor for anomalous credential reuse patterns to prevent lateral propagation.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector