Arweave Supply Chain Attack Stole Developer Credentials Across 36 npm Packages
Attackers compromised a maintainer account and pushed malicious updates to 36 npm packages with IronWorm, a sophisticated Rust-based infostealer that targeted SSH keys, AWS tokens, and crypto wallets. The malware used eBPF rootkits and GitHub tokens to self-replicate across repositories, affecting major organizations like Arweave and WeaveDB.









