IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
2026-06-05T19:24:11Z•86ee0d3b72367bc0f6709ce45cf42cda65ebda08b11df8ec39a7cf066f6fe7b3
AsinCISA-KEVChina-linkedGitHub-tokenIISMicrosoft-365-androidOP-512RCESMTP-relayandroid-spywarecloud-compromiseeBPFexploited-in-the-wildinformation-stealermacOS-backdoormalspammalvertisingnpmsupply-chaintoken-theftweb-shellworm
What happened
A large set of high-impact threats and active exploit campaigns were reported: npm supply-chain attacks distributing a Rust information stealer (IronWorm) and a self-spreading Miasma worm variant; an Android spyware family (Asin) targeting Arabic-speaking users via fake news, PDF and map apps; and a newly observed espionage cluster OP-512 deploying a bespoke IIS web shell framework (assessed as China-linked). Multiple critical vulnerabilities are being patched or actively exploited (notably Everest Forms Pro RCE and a Mirasvit Magento RCE added to CISA KEV), Cisco Unified CM and Redis RCEs (Po
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 86ee0d3b72367bc0f6709ce45cf42cda65ebda08b11df8ec39a7cf066f6fe7b3
- Enrichment time
- 2026-06-05T19:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.