Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
    Gold Bitcoin coin on a city street in front of a green rising candlestick chart showing BTC at $78,816.11
    Inside Crypto’s Fastest Week of 2026: Bitcoin’s August Price Rally Was Not a Retail Story
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

IronWorm Malware Targets Web3 Developers via Compromised npm Packages

Discovered by JFrog, the self-propagating infostealer deploys eBPF rootkits, steals Exodus wallets, and uses OIDC tokens to automatically infect software supply chains.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2026-06-04·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
IronWorm Malware Targets Web3 Developers via Compromised npm Packages

Key Highlights

  • IronWorm malware spreads via npm packages, targeting crypto devs and stealing wallet keys, tokens, and cloud credentials.
  • SlowMist warns Rust-based IronWorm can hijack GitHub repos and republish infected code across supply chains automatically.
  • Security firms say the attack creates a self-spreading loop, widening risk across Web3 projects and open-source ecosystems.

Security researchers have identified a new cyberattack targeting the cryptocurrency development ecosystem, warning that it is actively spreading through software tools used by developers.

In a post on X, security firm SlowMist said the malware, called IronWorm, is an advanced, Rust-based infostealer designed to slip past traditional code audits. Once installed, it is designed to steal sensitive information, including crypto wallet credentials, cloud access keys, GitHub tokens, and other development-related login details. 

🚨 SlowMist TI Alert 🚨

A new Rust-based supply-chain malware campaign, IronWorm, actively targeting developer environments and Web3/crypto ecosystems via malicious npm packages.

Potential attacker actions include credential theft, wallet seed and password theft, GitHub… pic.twitter.com/3ZgDHmrIuw

— SlowMist (@SlowMist_Team) June 4, 2026

The concern is that it moves through trusted software supply chains, meaning one infected package can expose multiple projects and developers. According to SlowMist and JFrog Security Research, the malware goes further than simple theft. It can alter code repositories and republish infected software, effectively helping it spread on its own. 

That creates a cycle where compromised accounts are used to distribute more malicious packages, widening the impact across open-source projects and Web3 applications. 

JFrog uncovers sophisticated attack chain

JFrog’s investigation found that the attack was distributed through npm packages linked to an account called asteroiddao. According to the findings, attackers re-uploaded legitimate-looking packages but embedded hidden Linux-based malware inside the installation files.

The infection was triggered automatically during installation through npm’s preinstall scripts. In practice, this meant developers could be compromised simply by running a normal package install. One of the packages under review, weavedb-sdk@0.45.3, drew attention after it showed unusual behavior during execution.

Further analysis showed the malware was intentionally designed to be difficult to detect. It used encrypted strings, a modified version of the UPX packing tool, and complex Rust-based code to slow down reverse engineering efforts. Once researchers managed to unpack the code, they found components linked to GitHub APIs, credential theft, and self-spreading mechanisms.

JFrog also reported 57 fake commits spread across nine different organizations. The attackers disguised these changes as routine maintenance work and attributed them to trusted automation identities such as “claude,” “dependabot,” and “github-actions,” making the activity appear legitimate at first glance.

Wallet theft and rootkit capabilities

Researchers say IronWorm is built to aggressively collect developer credentials across a wide range of systems. It goes after cloud services like AWS, container setups such as Kubernetes and Docker, AI development platforms, and cryptocurrency wallets.

The malware also includes a specific component aimed at the Exodus wallet, where it attempts to capture passwords and recovery phrases as users enter them.

Beyond data theft, it is designed to stay hidden on infected systems. Investigators found it deploys an eBPF rootkit, which allows it to conceal running processes and network activity. It also relies on Tor-based servers to receive instructions and send stolen data out of infected machines, making its traffic harder to trace.

Despite its sophistication, researchers noted operational mistakes in the code. The malware contained debugging data, and in one case exposed a hardcoded wallet recovery phrase believed to belong to the operator behind the campaign.

Supply-chain threats continue growing

IronWorm is the latest in a series of supply-chain attacks targeting software developers this year. In May, the TrapDoor campaign was reported, with attackers using npm, PyPI, and Crates.io packages to reach developers working in crypto, DeFi, artificial intelligence, and cybersecurity.

More recently, security firm SlowMist warned about another strain called Mini Shai-Hulud, which was found to have compromised more than 170 JavaScript packages. The malware spread through widely used open-source libraries, increasing the scale of exposure. Earlier in the year, attackers also breached Axios package releases after gaining access to publishing credentials..

Also Read: US Lawmakers Urge FTC to Investigate Kalshi & Polymarket’s Practices

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackWeb3
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Collage of CLARITY Act document, FOMC dot plot, and VeChain branding
Crypto Week Ahead: CLARITY Act Cloture, FOMC Dot Plot, BoJ Hike & VeChain Interstellar
Donald Trump speaking at a podium in the White House press briefing room
Trump Agrees to CLARITY Ethics Terms as Final Text Adds State AG Enforcement
Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Offers Attacker 20% Bounty
Symbiosis Recovers 15 BTC After Bitcoin Bridge Exploit, Offers Attacker 20% Bounty
CLARITY Act bill document in the US Senate with US Capitol building background
Senate Unveils Final CLARITY Act Text With Trump-Backed Ethics Deal Ahead of Tuesday Cloture Vote
CLARITY Act: Warren Davidson Pushes to Strip Section 305 Before Tuesday's Senate Vote
CLARITY Act: Warren Davidson Pushes to Strip Section 305 Before Tuesday’s Senate Vote

Find Us on Socials

You may also like

Ampleforth Proposal 54 Puts $2.5M USDC Treasury at Risk as Voting Opens Monday

Ampleforth Proposal 54 Puts $2.5M USDC Treasury at Risk as Voting Opens Monday

Chainflip Halts Network After $736K Tron USDT Exploit; Users to Be Made Whole

Chainflip Halts Network After $736K Tron USDT Exploit; Users to Be Made Whole

Optim Finance Pauses OADA After Splash Pool Exploit Drains Cardano Liquidity

Optim Finance Pauses OADA After Splash Pool Exploit Drains Cardano Liquidity

Zentra Finance logo on a soft orange and white gradient background.

Zentra Finance Reports $143K Exploit Affecting ctUSD Reserve

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information