SlowMist Discovers IronWorm Malware Targeting the Web3 Ecosystem via npm Packages

iconAiCoin
Share
AI summary iconSummary
Web3 news emerged as SlowMist uncovered IronWorm, a Rust-based supply chain malware that exploits npm packages to target the Web3 adoption ecosystem. The malware steals credentials, wallet mnemonics, and passwords, manipulates GitHub repositories, and leaks CI/CD secrets. Security teams are advised to trace commits, inspect for suspicious branches, and review unexpected build hooks. The threat uses Tor for command-and-control and eBPF rootkits for concealment. Developers should audit package sources and monitor automated identity submissions. Web3 adoption faces new risks as this malware spreads through developer tools.

SlowMist monitoring has detected a new Rust supply chain malware, IronWorm, targeting developer environments and the Web3 ecosystem through malicious npm packages. Attack activities include credential theft, harvesting wallet mnemonics and passwords, GitHub repository tampering, distribution of malicious packages, leakage of CI/CD secrets, Tor-based command-and-control, and eBPF rootkit stealth. Security teams should review commit histories, suspicious branches, unexpected build hooks, and automated identity commits.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.