Rust-Written IronWorm Hits NPM Supply Chain
2026-06-05T02:51:44Z•5cfb17bb6a6c01e094de93816e4d39bcea1161d187a5eb559dda1f088e5a4755
BTMOB-RAT」「Silent-Ransom-GroupMegalodonTA4922TeamPCPactive-exploitai-assisted-exploit-developmentclickfixcredential-theftdeveloper-targetingdrivesurgeedr-evasionemail-compromisefakeupdategithubglobalprotectkali365npmpan-osphishingphishing-as-a-serviceratrustsupply-chainxeno-ratzero-day
What happened
A DarkReading roundup highlighting multiple active, high-impact threats: supply-chain malware (Rust-written IronWorm targeting NPM; Megalodon pushing malicious commits to thousands of GitHub repos) and credential-stealing campaigns that propagate through developer tooling. Active exploitation and urgent patching needs are reported (a PAN-OS GlobalProtect authentication-bypass under active exploit), alongside expanding phishing-as-a-service and TDS operations (Kali365, DriveSurge delivering ClickFix/FakeUpdate). Attackers are increasingly using AI to automate EDR evasion and accelerate exploit/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 5cfb17bb6a6c01e094de93816e4d39bcea1161d187a5eb559dda1f088e5a4755
- Enrichment time
- 2026-06-05T02:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.