malware npm

weavedb-console

discovered 2026-06-03

IronWorm trojanized npm package published from compromised `asteroiddao` account.

Threat types

credential_stealer worm data_exfiltration

Malicious versions

  • 0.2.1

Campaigns