Daniel Reeves, Author at Phoenix Security
Author: Daniel Reeves
- 4th June 2026
IronWorm (No CVE): Rust-Built npm Worm Ships an eBPF Rootkit, Tor C2, and a Self-Propagating Supply Chain Implant Across 37 Packages
IronWorm is a Rust-built npm supply chain worm that distributed a 976 KB eBPF rootkit and Tor C2 across 37 packages from a single compromised account, with no CVE assigned. It uses npm’s own Trusted Publishing OIDC flow to mint publish credentials from CI runners and self-replicate. CVE-based scanners had zero detection surface at the point of compromise.
Daniel Reeves
Resources
Discover our events
Read More
Explore the talks
Read More
Discover Whitepapers
Read More
Read the latest News
Read More
Discover video resources
Learn More
Listen to the latest AppSec Phoenix podcast
Read More
Welcome to Peace of Mind
Trusted by more than 1000 users and 380 organizations