Daniel Reeves, Author at Phoenix Security

Author: Daniel Reeves

IronWorm (No CVE): Rust-Built npm Worm Ships an eBPF Rootkit, Tor C2, and a Self-Propagating Supply Chain Implant Across 37 Packages

IronWorm is a Rust-built npm supply chain worm that distributed a 976 KB eBPF rootkit and Tor C2 across 37 packages from a single compromised account, with no CVE assigned. It uses npm’s own Trusted Publishing OIDC flow to mint publish credentials from CI runners and self-replicate. CVE-based scanners had zero detection surface at the point of compromise.

Daniel Reeves

Resources

Discover our events
Read More

Explore the talks
Read More

Discover Whitepapers
Read More

Read the latest News
Read More

Discover video resources
Learn More

Listen to the latest AppSec Phoenix podcast
Read More

Welcome to Peace of Mind

Trusted by more than 1000 users and 380 organizations

ACT Now
Request a demo