Supply chain attacks are now deploying rootkits 😳 fyi it’s gg once a rootkit is found, best practices dictate a complete format and reinstall of the computer
In case of Ironworm it’s more tedious; you gotta *carefully* rotate credentials and audit your git repos / workflows too. Btw remember shai halud dead man switch that deletes your home directory if it detected its credentials got revoked? 💀
Say you’re careful, how can you be so sure about your agent? It can get prompt injected by a webpage or file (see AI Agent Traps paper by Google Deepmind).
Time to airgap our dev machines to like a cloud VM to limit some blast radius.
⚠️ New "IronWorm" supply-chain attack: 30 npm packages from @ asteroiddao shipped a malicious Rust binary firing on preinstall.
It sweeps 86 env vars 20 credential files (AWS, GCP, Vault, npm, plus AI keys like Anthropic & OpenAI), hits Exodus wallets, hides behind an eBPF rootkit, and beacons over Tor. Self-propagates via npm Trusted Publishing OIDC, with backdated commits faked as claude/dependabot/renovate.