ended6월 15일· 1 sources

IronWorm Masquerades as AI Assistant to Compromise Developer Credentials

AI 어시스턴트로 위장한 공급망 공격 IronWorm, API 키 대량 탈취

Why it matters

IronWorm represents a watershed moment in supply chain attacks by impersonating trusted AI coding assistants in git commits while harvesting Anthropic and OpenAI API keys—credentials with immediate monetary value and potential for lateral escalation. The attack also exposes a critical weakness in npm's Trusted Publishing: provenance signatures can be forged through CI/CD pipeline compromise, making them insufficient as standalone trust signals for package integrity.

1
Sources
+0
24h
Growth
97d
Active
IronWormsupply chain attackAPI credentialsnpm packagesTrusted Publishing

Sources

Related Issues