Rust-Written IronWorm Hits NPM Supply Chain

2026-06-05T02:51:44Z5cfb17bb6a6c01e094de93816e4d39bcea1161d187a5eb559dda1f088e5a4755
BTMOB-RAT」「Silent-Ransom-GroupMegalodonTA4922TeamPCPactive-exploitai-assisted-exploit-developmentclickfixcredential-theftdeveloper-targetingdrivesurgeedr-evasionemail-compromisefakeupdategithubglobalprotectkali365npmpan-osphishingphishing-as-a-serviceratrustsupply-chainxeno-ratzero-day

What happened

A DarkReading roundup highlighting multiple active, high-impact threats: supply-chain malware (Rust-written IronWorm targeting NPM; Megalodon pushing malicious commits to thousands of GitHub repos) and credential-stealing campaigns that propagate through developer tooling. Active exploitation and urgent patching needs are reported (a PAN-OS GlobalProtect authentication-bypass under active exploit), alongside expanding phishing-as-a-service and TDS operations (Kali365, DriveSurge delivering ClickFix/FakeUpdate). Attackers are increasingly using AI to automate EDR evasion and accelerate exploit/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
5cfb17bb6a6c01e094de93816e4d39bcea1161d187a5eb559dda1f088e5a4755
Enrichment time
2026-06-05T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.