Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    The Robinhood Chain Paradox Built for Tokenized Stocks, Dominated by Memecoins
    The Robinhood Chain Paradox: Built for Tokenized Stocks, Dominated by Memecoins
    Senators to Brief Trump on CLARITY Act Path - Here's What to Expect
    Senators to Brief Trump on CLARITY Act Path – Here’s What to Expect
  • Opinion
    OpinionShow More
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

IronWorm Malware Targets Web3 Developers via Compromised npm Packages

Discovered by JFrog, the self-propagating infostealer deploys eBPF rootkits, steals Exodus wallets, and uses OIDC tokens to automatically infect software supply chains.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2026-06-04·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
IronWorm Malware Targets Web3 Developers via Compromised npm Packages

Key Highlights

  • IronWorm malware spreads via npm packages, targeting crypto devs and stealing wallet keys, tokens, and cloud credentials.
  • SlowMist warns Rust-based IronWorm can hijack GitHub repos and republish infected code across supply chains automatically.
  • Security firms say the attack creates a self-spreading loop, widening risk across Web3 projects and open-source ecosystems.

Security researchers have identified a new cyberattack targeting the cryptocurrency development ecosystem, warning that it is actively spreading through software tools used by developers.

In a post on X, security firm SlowMist said the malware, called IronWorm, is an advanced, Rust-based infostealer designed to slip past traditional code audits. Once installed, it is designed to steal sensitive information, including crypto wallet credentials, cloud access keys, GitHub tokens, and other development-related login details. 

🚨 SlowMist TI Alert 🚨

A new Rust-based supply-chain malware campaign, IronWorm, actively targeting developer environments and Web3/crypto ecosystems via malicious npm packages.

Potential attacker actions include credential theft, wallet seed and password theft, GitHub… pic.twitter.com/3ZgDHmrIuw

— SlowMist (@SlowMist_Team) June 4, 2026

The concern is that it moves through trusted software supply chains, meaning one infected package can expose multiple projects and developers. According to SlowMist and JFrog Security Research, the malware goes further than simple theft. It can alter code repositories and republish infected software, effectively helping it spread on its own. 

That creates a cycle where compromised accounts are used to distribute more malicious packages, widening the impact across open-source projects and Web3 applications. 

JFrog uncovers sophisticated attack chain

JFrog’s investigation found that the attack was distributed through npm packages linked to an account called asteroiddao. According to the findings, attackers re-uploaded legitimate-looking packages but embedded hidden Linux-based malware inside the installation files.

The infection was triggered automatically during installation through npm’s preinstall scripts. In practice, this meant developers could be compromised simply by running a normal package install. One of the packages under review, weavedb-sdk@0.45.3, drew attention after it showed unusual behavior during execution.

Further analysis showed the malware was intentionally designed to be difficult to detect. It used encrypted strings, a modified version of the UPX packing tool, and complex Rust-based code to slow down reverse engineering efforts. Once researchers managed to unpack the code, they found components linked to GitHub APIs, credential theft, and self-spreading mechanisms.

JFrog also reported 57 fake commits spread across nine different organizations. The attackers disguised these changes as routine maintenance work and attributed them to trusted automation identities such as “claude,” “dependabot,” and “github-actions,” making the activity appear legitimate at first glance.

Wallet theft and rootkit capabilities

Researchers say IronWorm is built to aggressively collect developer credentials across a wide range of systems. It goes after cloud services like AWS, container setups such as Kubernetes and Docker, AI development platforms, and cryptocurrency wallets.

The malware also includes a specific component aimed at the Exodus wallet, where it attempts to capture passwords and recovery phrases as users enter them.

Beyond data theft, it is designed to stay hidden on infected systems. Investigators found it deploys an eBPF rootkit, which allows it to conceal running processes and network activity. It also relies on Tor-based servers to receive instructions and send stolen data out of infected machines, making its traffic harder to trace.

Despite its sophistication, researchers noted operational mistakes in the code. The malware contained debugging data, and in one case exposed a hardcoded wallet recovery phrase believed to belong to the operator behind the campaign.

Supply-chain threats continue growing

IronWorm is the latest in a series of supply-chain attacks targeting software developers this year. In May, the TrapDoor campaign was reported, with attackers using npm, PyPI, and Crates.io packages to reach developers working in crypto, DeFi, artificial intelligence, and cybersecurity.

More recently, security firm SlowMist warned about another strain called Mini Shai-Hulud, which was found to have compromised more than 170 JavaScript packages. The malware spread through widely used open-source libraries, increasing the scale of exposure. Earlier in the year, attackers also breached Axios package releases after gaining access to publishing credentials..

Also Read: US Lawmakers Urge FTC to Investigate Kalshi & Polymarket’s Practices

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto HackWeb3
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Crypto ETFs End the Week With Strong Inflows Despite Bitcoin $225M Outflow
Crypto ETFs End Week Positive Despite $465M Bitcoin Outflows
Tokenized SpaceX Overtakes GameStop on Robinhood Chain as RWAs Explode 5x to $70M
Tokenized SpaceX Overtakes GameStop on Robinhood Chain as RWAs Explode 5x to $70M
Phantom Pulls the Plug on Monad Less Than a Year After Launch
Phantom Pulls the Plug on Monad Less Than a Year After Launch
The Trump Crypto Presidency Power, Policy, and $1.4 Billion
The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
Take Trump Ethics Deal or Watch CLARITY Act Fail, White House Warns
Take Trump Ethics Deal or Watch CLARITY Act Fail: White House Warns 

Find Us on Socials

You may also like

Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana

Triple-A Hot Wallets Drained of $9.3M Across TRON, Ethereum, TON & Solana

Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit

Ethereum DeFi Protocol Lien Finance Hacked for $542K in USDC Exploit

$44.4M ETH Moved Drift Protocol Exploiter Breaks 3-Month Silence

$44.4M ETH Moved: Drift Protocol Exploiter Breaks 3-Month Silence

Odos Urges Users to Move Assets Before July 30 Shutdown

Odos Urges Users to Move Assets Before July 30 Shutdown

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information