Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware Strikes npm with IronWorm and Miasma Variants

New Malware Strikes npm with IronWorm and Miasma Variants

Posted on June 5, 2026 By CWS

In a significant cybersecurity event, the npm ecosystem has been targeted by multiple software supply chain attacks. Threat actors have managed to compromise over 50 legitimate packages, using them to disseminate a Rust-based information stealer and a self-replicating worm. This new wave of attacks marks a worrying trend in the use of npm packages for malicious activities.

Unveiling the IronWorm Threat

JFrog, a leading software supply chain security company, has identified a new malware named IronWorm. This malware is designed to extract sensitive information from developers’ machines, concealed by an eBPF kernel rootkit. It communicates with its operators through the Tor network, ensuring anonymity. IronWorm leverages stolen credentials to propagate itself, reminiscent of the notorious Shai-Hulud worm.

The attack appears to originate from a compromised npm account, ‘asteroiddao’, which published packages containing the malicious Rust ELF binary. This binary executes via a preinstall hook, targeting numerous environment variables and files that hold credentials for services like OpenAI, AWS, and Docker. Interestingly, the wallet-stealing component excludes the threat actor’s own wallet, indicating a level of sophistication in its design.

Miasma Worm’s Resurgence

In parallel, a separate malware campaign has emerged, involving a variant of the Miasma worm. Discovered by Endor Labs and StepSecurity, this attack has compromised 57 npm packages with over 286 malicious versions. The Miasma worm exploits a unique technique termed ‘Phantom Gyp’, facilitating code execution during npm install without triggering standard security checks.

The reemergence of Miasma has been linked to a compromised GitHub account, which facilitated unauthorized commits to various repositories. The malware targets credentials from services such as AWS, Google Cloud, and GitHub Actions, among others. Notably, it also embeds persistent backdoors in project repositories, activating whenever a developer uses an AI-assisted Integrated Development Environment (IDE).

Implications and Future Outlook

These attacks underscore the vulnerability of software supply chains and the evolving tactics of cybercriminals. Developers are urged to rotate credentials, disable install scripts, and ensure package integrity to mitigate risks. The Miasma worm, in particular, showcases adaptive capabilities, using public platforms like GitHub for command-and-control operations, complicating detection efforts.

As the cybersecurity landscape shifts, organizations must remain vigilant, enhancing their monitoring and response strategies. The ongoing developments in the IronWorm and Miasma campaigns highlight the need for robust security measures and heightened awareness among developers to safeguard critical infrastructure.

The Hacker News Tags:AI, Cryptocurrency, Cybersecurity, GitHub, IronWorm, Malware, Miasma, NPM, Rust, Security, supply chain attack

Post navigation

Previous Post: OWASP Project Enhances Security by Identifying Vulnerable Dependencies

Related Posts

A Healthcare CISO’s Journey to Enabling Modern Care A Healthcare CISO’s Journey to Enabling Modern Care The Hacker News
Emerging Cyber Threats and Security Flaws Reviewed Emerging Cyber Threats and Security Flaws Reviewed The Hacker News
Germany Shuts Down eXch Over .9B Laundering, Seizes €34M in Crypto and 8TB of Data Germany Shuts Down eXch Over $1.9B Laundering, Seizes €34M in Crypto and 8TB of Data The Hacker News
Echo Chamber Jailbreak Tricks LLMs Like OpenAI and Google into Generating Harmful Content Echo Chamber Jailbreak Tricks LLMs Like OpenAI and Google into Generating Harmful Content The Hacker News
AI-Powered Slopoly Malware Boosts Hive0163’s Ransomware Tactics AI-Powered Slopoly Malware Boosts Hive0163’s Ransomware Tactics The Hacker News
Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark