IronWorm npm supply-chain infection and self-propagation
Malware Activity
Updated: 04.06.2026 18:25
· First: 04.06.2026 18:25
· 📰 1 src / 1 articles
· H score: 21
The IronWorm malware has infected 36 npm packages, creating a supply-chain risk for developer and CI environments that can leak secrets and receive trojanized updates. It targets 86 environment variables and 20 credential files, including OpenAI, AWS, Anthropic, and npm credentials, plus SSH keys and Exodus wallet files. The malware also self-propagates by stealing publishing credentials, including secrets tied to npm Trusted Publishing, so a single compromise can spread to more packages.