ended6월 15일· 1 sources
IronWorm Masquerades as AI Assistant to Compromise Developer Credentials
AI 어시스턴트로 위장한 공급망 공격 IronWorm, API 키 대량 탈취
Why it matters
IronWorm represents a watershed moment in supply chain attacks by impersonating trusted AI coding assistants in git commits while harvesting Anthropic and OpenAI API keys—credentials with immediate monetary value and potential for lateral escalation. The attack also exposes a critical weakness in npm's Trusted Publishing: provenance signatures can be forged through CI/CD pipeline compromise, making them insufficient as standalone trust signals for package integrity.
1
Sources
+0
24h
—
Growth
97d
Active
IronWormsupply chain attackAPI credentialsnpm packagesTrusted Publishing