Odaily Planet Daily reports that SlowMist posted on X that its threat intelligence system has detected a new Rust-based supply chain malware campaign named IronWorm, which is actively targeting developer environments and the Web3/crypto ecosystem through malicious npm packages. Potential attack behaviors include credential theft, harvesting wallet mnemonics and passwords, GitHub repository tampering, distribution of malicious packages, theft of CI/CD keys, Tor-based command-and-control, and persistent concealment via eBPF rootkits.
SlowMist recommends that security teams audit retroactive commits, suspicious branches, and anomalous build hooks within the repository, as well as commits attributed to automated identities such as claude, dependabot, renovate, or github-actions; remove or deprecate affected package versions, release a clean version, rotate all exposed keys and tokens, review GitHub Actions build artifacts, and rebuild potentially compromised developer or CI systems from clean images. This threat was discovered and analyzed by JFrogSecurity.





