## Author: Daniel Reeves

- 4th June 2026

## [IronWorm (No CVE): Rust-Built npm Worm Ships an eBPF Rootkit, Tor C2, and a Self-Propagating Supply Chain Implant Across 37 Packages](/content/ironworm-npm-supply-chain-worm-rust-ebpf-rootkit-tor/index.html)

IronWorm is a Rust-built npm supply chain worm that distributed a 976 KB eBPF rootkit and Tor C2 across 37 packages from a single compromised account, with no CVE assigned. It uses npm’s own Trusted Publishing OIDC flow to mint publish credentials from CI runners and self-replicate. CVE-based scanners had zero detection surface at the point of compromise.

Daniel Reeves

### Resources

Discover our events  
[Read More](/content/live-events/index.html)

Explore the talks  
[Read More](/content/podcasts/index.html)

Discover Whitepapers  
[Read More](/content/download-whitepaper-data-driven-vuln-management-are-sla-dead/index.html)

Read the latest News  
[Read More](/content/blog/index.html)

Discover video resources  
[Learn More](/content/videos/index.html)

Listen to the latest AppSec Phoenix podcast  
[Read More](/content/podcasts/index.html)

### Welcome to Peace of Mind

Trusted by more than 1000 users and 380 organizations

[ACT Now](/content/act-now-get-access/index.html)  
[Request a demo](/content/request-a-demo/index.html)
