VMTech
Discuss a project

IronWorm and Miasma target npm: secret theft and self‑propagation

IronWorm and Miasma target npm: secret theft and self‑propagation

Colleagues, note major supply‑chain attacks observed in npm.

- IronWorm (JFrog): Rust stealer with eBPF rootkit and Tor, spread via trojanized releases from compromised asteroiddao account; steals env vars, cloud keys, AI‑assistant configs and wallets.
- New Miasma variant (Endor Labs/StepSecurity): >50 packages, "Phantom Gyp" (binding.gyp) and Bun loader to extract secrets, including from AI‑IDEs.
- Mitigation: revoke/rotate keys, disable install‑scripts and native rebuilds, pin packages with integrity hashes, audit CI/Actions.

Why it matters: malicious code propagates via supply chain and exfiltrates secrets.

What will you change in your security processes?

#cybersecurity #supplychain #npm #DevSecOps

Open analytics
On the site 1 views
min read 1 05.06.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

IronWorm and Miasma target npm: secret theft and self‑propagation

Open the post on Instagram ↗