malware npm

weavedb-exm-sdk-web

discovered 2026-06-03

IronWorm trojanized npm package published from compromised `asteroiddao` account.

Threat types

credential_stealer worm data_exfiltration

Malicious versions

  • 0.7.4

Campaigns