npm

weavedb-node-client

IronWorm trojanized npm package published from compromised `asteroiddao` account.

discovered 2026-06-03

Threat types

credential_stealerwormdata_exfiltration

Malicious versions

  • 0.45.3

Campaigns