IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

2026-06-05T19:24:11Z86ee0d3b72367bc0f6709ce45cf42cda65ebda08b11df8ec39a7cf066f6fe7b3
AsinCISA-KEVChina-linkedGitHub-tokenIISMicrosoft-365-androidOP-512RCESMTP-relayandroid-spywarecloud-compromiseeBPFexploited-in-the-wildinformation-stealermacOS-backdoormalspammalvertisingnpmsupply-chaintoken-theftweb-shellworm

What happened

A large set of high-impact threats and active exploit campaigns were reported: npm supply-chain attacks distributing a Rust information stealer (IronWorm) and a self-spreading Miasma worm variant; an Android spyware family (Asin) targeting Arabic-speaking users via fake news, PDF and map apps; and a newly observed espionage cluster OP-512 deploying a bespoke IIS web shell framework (assessed as China-linked). Multiple critical vulnerabilities are being patched or actively exploited (notably Everest Forms Pro RCE and a Mirasvit Magento RCE added to CISA KEV), Cisco Unified CM and Redis RCEs (Po

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
86ee0d3b72367bc0f6709ce45cf42cda65ebda08b11df8ec39a7cf066f6fe7b3
Enrichment time
2026-06-05T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks · Baitaphish