IronWorm is a suspected software supply-chain threat cluster associated with malicious npm activity targeting developer workstations and CI environments. The name has been used in connection with campaigns that delivered Rust-based malware through trojanized packages, including use of npm lifecycle hooks such as preinstall to execute embedded native payloads. Reported tradecraft includes credential theft from developer ecosystems, collection of cloud and application secrets, and Linux-focused post-compromise capabilities. The malware associated with this cluster has been described as using an eBPF rootkit for stealth on Linux and Tor for command-and-control communications, indicating an emphasis on evasion and resilient operator access. Observed targeting aligns with high-value developer and build environments rather than broad consumer infection. Such operations are designed to compromise software maintainers, package consumers, and downstream enterprise environments by abusing trusted package distribution channels. Techniques attributed in reporting include package account compromise or abuse of package publishing workflows, embedding cross-platform native binaries inside packages, and shifting execution from install-time hooks to runtime JavaScript in order to evade defenses that only inspect lifecycle scripts. IronWorm has been referenced alongside other 2026 supply-chain campaigns involving malicious open-source packages, but no confirmed public attribution links it to those clusters. In particular, similarity in delivery methods has been noted with other npm package compromises, yet any direct relationship remains unconfirmed. Publicly available information does not currently support a reliable attribution to a specific nation state, criminal organization, or named intrusion set beyond the IronWorm label itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate npm supply-chain campaign involving a Rust malware payload, eBPF rootkit capability, Tor communications, and self-propagation via stolen npm and GitHub credentials.
Referenced as a prior campaign with a similar npm preinstall-script execution pattern involving an embedded binary.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.