Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware Strikes npm with IronWorm and Miasma Variants

New Malware Strikes npm with IronWorm and Miasma Variants

Posted on June 5, 2026 By CWS

In a significant cybersecurity event, the npm ecosystem has been targeted by multiple software supply chain attacks. Threat actors have managed to compromise over 50 legitimate packages, using them to disseminate a Rust-based information stealer and a self-replicating worm. This new wave of attacks marks a worrying trend in the use of npm packages for malicious activities.

Unveiling the IronWorm Threat

JFrog, a leading software supply chain security company, has identified a new malware named IronWorm. This malware is designed to extract sensitive information from developers’ machines, concealed by an eBPF kernel rootkit. It communicates with its operators through the Tor network, ensuring anonymity. IronWorm leverages stolen credentials to propagate itself, reminiscent of the notorious Shai-Hulud worm.

The attack appears to originate from a compromised npm account, ‘asteroiddao’, which published packages containing the malicious Rust ELF binary. This binary executes via a preinstall hook, targeting numerous environment variables and files that hold credentials for services like OpenAI, AWS, and Docker. Interestingly, the wallet-stealing component excludes the threat actor’s own wallet, indicating a level of sophistication in its design.

Miasma Worm’s Resurgence

In parallel, a separate malware campaign has emerged, involving a variant of the Miasma worm. Discovered by Endor Labs and StepSecurity, this attack has compromised 57 npm packages with over 286 malicious versions. The Miasma worm exploits a unique technique termed ‘Phantom Gyp’, facilitating code execution during npm install without triggering standard security checks.

The reemergence of Miasma has been linked to a compromised GitHub account, which facilitated unauthorized commits to various repositories. The malware targets credentials from services such as AWS, Google Cloud, and GitHub Actions, among others. Notably, it also embeds persistent backdoors in project repositories, activating whenever a developer uses an AI-assisted Integrated Development Environment (IDE).

Implications and Future Outlook

These attacks underscore the vulnerability of software supply chains and the evolving tactics of cybercriminals. Developers are urged to rotate credentials, disable install scripts, and ensure package integrity to mitigate risks. The Miasma worm, in particular, showcases adaptive capabilities, using public platforms like GitHub for command-and-control operations, complicating detection efforts.

As the cybersecurity landscape shifts, organizations must remain vigilant, enhancing their monitoring and response strategies. The ongoing developments in the IronWorm and Miasma campaigns highlight the need for robust security measures and heightened awareness among developers to safeguard critical infrastructure.

The Hacker News Tags:AI, Cryptocurrency, Cybersecurity, GitHub, IronWorm, Malware, Miasma, NPM, Rust, Security, supply chain attack

Post navigation

Previous Post: OWASP Project Enhances Security by Identifying Vulnerable Dependencies
Next Post: Hackers Exploit System Tools to Deploy Malware

Related Posts

Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition The Hacker News
Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam Researchers Expose SVG and PureRAT Phishing Threats Targeting Ukraine and Vietnam The Hacker News
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do The Hacker News
Overcoming Risks from Chinese GenAI Tool Usage Overcoming Risks from Chinese GenAI Tool Usage The Hacker News
SolarWinds Fixes Major Flaws in Serv-U Software SolarWinds Fixes Major Flaws in Serv-U Software The Hacker News
Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws Zoom and GitLab Release Security Updates Fixing RCE, DoS, and 2FA Bypass Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark