news.mlab.sh
Back to the feed
supply-chain

New IronWorm malware hits 36 packages in npm supply-chain attack

High
Summary

A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticated eBPF rootkit to propagate, highlighting vulnerabilities within the Node Package Manager ecosystem. This attack underscores the importance of robust supply chain security practices and proactive threat detection.

The attack began with a compromised npm account, ‘asteroiddao,’ which published malicious package versions containing the IronWorm malware. This malware, written in Rust and utilizing an eBPF kernel rootkit, self-propagates by leveraging stolen credentials to publish trojanized packages, infecting additional developers and CI systems. The operation’s complexity suggests a carefully constructed implant, potentially an evolution of TeamPCP’s payload, utilizing GitHub Actions to deliver stolen secrets as build artifacts, avoiding traditional C2 channels. Researchers discovered a concerning element – the threat actor hardcoded their own cryptocurrency wallet recovery phrase, likely for testing purposes. While the attack was detected early by Ox Security and prevented from widespread damage, it serves as a stark reminder of the potential for sophisticated supply-chain attacks to exploit developer workflows and CI/CD pipelines.

Read the full article at BleepingComputer