IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
EXPIRED
60.5
2026-06-06T07:00
Score-Aufschlüsselung
100
novelty
35
reach
45
concrete_impact
65
emotional_hook
70
source_quality
55
platform_fit
Zusammenfassung
Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively. According to JFrog, the information stealer "scrapes every secret it can find on a developer's machine, hides behind an eBPF kernel rootkit, and
Skripte (0)
e7fd81cb…
Noch kein Skript generiert.
Score 60.5 — unter Schwellwert (65)