Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIIronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
The npm ecosystem has been targeted by multiple supply chain attacks involving over 50 compromised packages. Threat actors deployed IronWorm, a Rust-based information stealer that uses eBPF kernel rootkit techniques to hide while harvesting credentials, and a new variant of the Miasma worm capable of self-propagation across developer environments.
AIRust-Written IronWorm Hits NPM Supply Chain
A new malware campaign called IronWorm, written in Rust, has been discovered targeting the NPM package ecosystem. The malware focuses on compromising developer credentials and leveraging them to spread laterally across the software supply chain, posing significant risks to enterprise development environments.
