Back Kucoin SlowMist Discovers IronWorm, a Rust supply chain malware targeting Web3 developers
Odaily Planet Daily reports that SlowMist posted on X that its threat intelligence system has detected a new Rust-based supply chain malware campaign named IronWorm, which is actively targeting developer environments and the Web3/crypto ecosystem through malicious npm packages. Potential attack behaviors include credential theft, harvesting wallet mnemonics and passwords, GitHub repository tampering, distribution of malicious packages, theft of CI/CD keys, Tor-based command-and-control, and persistent concealment via eBPF rootkits.
SlowMist recommends that security teams audit retroactive commits, suspicious branches, and anomalous build hooks within the repository, as well as commits attributed to automated identities such as claude, dependabot, renovate, or github-actions; remove or deprecate affected package versions, release a clean version, rotate all exposed keys and tokens, review GitHub Actions build artifacts, and rebuild potentially compromised developer or CI systems from clean images. This threat was discovered and analyzed by JFrogSecurity.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
