VibeSecCon Returns: The Security Summit Running From Prompt to Runtime. June 16th, 2026

IronWorm Supply Chain Malware Hits npm

IronWorm Supply Chain Malware Hits npm

Is it a bird? Is it a plane? No, it’s ANOTHER supply chain attack.

Overview

IronWorm is a self-replicating, Rust-built malware campaign targeting software developers via malicious NPM packages.
The malware targets environment variables, cloud credentials, and crypto wallets.
It self replicates by stealing credentials and uploading GitHub commits that automatically publish new malicious packages.
Kudos to JFrog for detecting and reporting this campaign.

Who is affected

Anyone installing the affected versions of the malicious packages (see below)

Impact

  • 36 packages were infected
  • 32,177 total monthly downloads
  • 148,724 total lifetime downloads
  1. Rotate your keys and add 2FA to your accounts
  2. Upgrade the affected packages to a fixed version

Affected Packages

Package name (npm)Affected versions
ai30.3.5
aonote0.11.1
arjson0.1.4
arnext0.1.5
arnext-arkb0.0.2
atomic-notes0.5.3
create-arnext-app0.0.10
cwao0.5.6
cwao-tools0.3.1
cwao-units0.8.3
fpjson-lang0.1.7
hbsig0.3.2
monade0.0.7
roidjs0.1.7
test-ajs0.1.19
test-weavedb-sdk1.1.1
testnpmnmp1.0.21
wao0.41.2
warp-contracts-plugin-deploy-test3.0.1
wdb-cli0.1.1
wdb-core0.1.2
wdb-sdk0.1.2
weavedb-base0.45.3
weavedb-client0.45.3
weavedb-console0.2.1
weavedb-contracts0.45.2
weavedb-exm-sdk0.7.4
weavedb-exm-sdk-web0.7.4
weavedb-node-client0.45.3
weavedb-offchain0.45.4
weavedb-sdk0.45.3
weavedb-sdk-base0.21.1
weavedb-sdk-node0.45.3
weavedb-tools0.45.3
weavedb-warp-contracts-plugin-deploy1.0.11
zkjson0.8.5

Tags:

post banner image

Run Every Security Test Your Code Needs

Pinpoint, investigate and eliminate code-level issues across the entire SDLC.

GET A PERSONALIZED DEMO
Frame 2085668530

Subscribe to Our Newsletter

Stay updated with the latest SaaS insights, tips, and news delivered straight to your inbox.

Group 1261154229