
Someone hid a self-replicating worm inside 37 npm packages.
Written in Rust.
Hidden behind an eBPF kernel rootkit.
Talking to its operator over Tor.
It steals 86 environment variables.
AWS keys. GCP keys. Vault secrets. Kubernetes tokens.
Your Anthropic API key. Your OpenAI key.
Your Exodus wallet seed phrase.
Then it uses your own npm credentials to republish itself into your packages.
So your code infects the next developer.
Who infects the next one.
The commits were backdated up to 13 years.
The commit author name was “claude.”
The malware named itself after the AI to hide in plain sight.
The attacker also left their own wallet recovery phrase in the debug data.
Nobody is having a good day.
Check your preinstall hooks.
Aikido Security@AikidoSecurity
⚠️ New "IronWorm" supply-chain attack: 30+ npm packages from @ asteroiddao shipped a malicious Rust binary firing on preinstall. It sweeps 86 env vars + 20 credential files (AWS, GCP, Vault, npm, plus AI keys like Anthropic & OpenAI), hits Exodus wallets, hides behind an eBPF rootkit, and beacons over Tor. Self-propagates via npm Trusted Publishing OIDC, with backdated commits faked as claude/dependabot/renovate.
English



















