npm

weavedb-exm-sdk

IronWorm trojanized npm package published from compromised `asteroiddao` account.

discovered 2026-06-03

Threat types

credential_stealerwormdata_exfiltration

Malicious versions

  • 0.7.4

Campaigns