A new malware called IronWorm written in Rust is targeting npm package developers to steal their credentials and use those stolen credentials to compromise additional packages and spread through the software supply chain. You should monitor your developer
Read the full article: https://www.darkreading.com/cyberattacks-data-breaches/rust-written-ironworm-npm-supply-chain