Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

New IronWorm malware hits 36 packages in npm supply-chain attack

A supply-chain attack infected 36 packages on npm with IronWorm infostealer malware. The attack compromised multiple packages in the Node Package Manager ecosystem, potentially affecting downstream users and applications.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
36 npm packages with potential widespread downstream impact depending on package popularity and usage
Ecosystems
Attack vectors
Threat actor
Affected entities
  • 36 npm packagesSpecific package names not provided in source text

A new supply-chain attack has compromised 36 packages on the Node Package Manager (npm) index with infostealer malware named IronWorm. The malicious packages were distributed through the npm registry, a critical infrastructure point for JavaScript/Node.js development.

The IronWorm malware is designed to steal information from affected systems. With 36 packages compromised, the potential blast radius extends to any developer or application that installed these packages as dependencies.

The attack represents a direct compromise of the npm supply chain, affecting the integrity of packages available to millions of developers worldwide.

Remediation

  • Identify and audit all npm packages installed in your projects for the 36 affected packages
  • Remove or update any affected packages immediately
  • Review package.lock or yarn.lock files for evidence of installation
  • Scan systems that may have executed code from affected packages for IronWorm malware indicators
  • Monitor npm security advisories for the specific package names and versions
  • Implement stricter package vetting and dependency scanning in your development pipeline

Sources

  1. New IronWorm malware hits 36 packages in npm supply-chain attack · BleepingComputer

Cite this entry

"New IronWorm malware hits 36 packages in npm supply-chain attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack-12l3ww

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in eth-codergen

    Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in fs-extra-core

    Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  3. containedcritical

    Malware in cktool-core

    Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  4. activecritical

    Malware in lychee-norm-cache

    Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package