SlowMist: IronWorm malware attacks Web3 ecosystem through npm package

AiCoin
AiCoin|6月 04, 2026 06:51
SlowMist Monitoring has discovered that the new Rust supply chain malware IronWorm is using malicious npm packages to attack developer environments and the Web3 ecosystem. The attack behaviors include credential theft, wallet mnemonic and password theft, GitHub repository tampering, malicious package publishing, CI/CD confidential leakage, Tor based command control, and eBPF rootkit invisibility. The security team needs to review backtracking submissions, suspicious branches, unexpected hook constructions, and automated identity submissions.
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads