IronWorm Rust Supply Chain Malware Targets Web3 Developers via Malicious npm Packages on June 4

According to Slow Mist's security monitoring on June 4, a new Rust supply chain malware campaign called IronWorm is attacking Web3 developers through malicious npm packages. The attack capabilities include credential theft, wallet seed phrase and password extraction, GitHub repository manipulation, malicious package publication, CI/CD secret exposure, Tor-based command and control, and eBPF rootkit persistence.

Security teams should audit repository history for suspicious commits, branches, and build hooks, particularly those from automated identities like claude, dependabot, renovate, or github-actions. Recommended actions include removing or deprecating affected package versions, publishing clean releases, rotating all exposed credentials and tokens, and rebuilding potentially compromised development and CI systems from clean images.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments