IronWorm Supply Chain Malware Hits npm

IronWorm Supply Chain Malware Hits npm
Share

Is it a bird? Is it a plane? No, it’s ANOTHER supply chain attack.

Overview

IronWorm is a self-replicating, Rust-built malware campaign targeting software developers via malicious NPM packages.
The malware targets environment variables, cloud credentials, and crypto wallets.
It self replicates by stealing credentials and uploading GitHub commits that automatically publish new malicious packages.
Kudos to JFrog for detecting and reporting this campaign.

Who is affected

Anyone installing the affected versions of the malicious packages (see below)

Impact

  • 36 packages were infected
  • 32,177 total monthly downloads
  • 148,724 total lifetime downloads
  1. Rotate your keys and add 2FA to your accounts
  2. Upgrade the affected packages to a fixed version

Affected Packages

Package name (npm)Affected versions
ai30.3.5
aonote0.11.1
arjson0.1.4
arnext0.1.5
arnext-arkb0.0.2
atomic-notes0.5.3
create-arnext-app0.0.10
cwao0.5.6
cwao-tools0.3.1
cwao-units0.8.3
fpjson-lang0.1.7
hbsig0.3.2
monade0.0.7
roidjs0.1.7
test-ajs0.1.19
test-weavedb-sdk1.1.1
testnpmnmp1.0.21
wao0.41.2
warp-contracts-plugin-deploy-test3.0.1
wdb-cli0.1.1
wdb-core0.1.2
wdb-sdk0.1.2
weavedb-base0.45.3
weavedb-client0.45.3
weavedb-console0.2.1
weavedb-contracts0.45.2
weavedb-exm-sdk0.7.4
weavedb-exm-sdk-web0.7.4
weavedb-node-client0.45.3
weavedb-offchain0.45.4
weavedb-sdk0.45.3
weavedb-sdk-base0.21.1
weavedb-sdk-node0.45.3
weavedb-tools0.45.3
weavedb-warp-contracts-plugin-deploy1.0.11
zkjson0.8.5

OX cloud 1

Active AI Defense. Complete Cloud Visibility.

Your agents hold identities you never issued. See what they touch, in real time.

Meet OX Cloud