Back Kucoin SlowMist Discovers IronWorm Malware Targeting the Web3 Ecosystem via npm Packages
SlowMist monitoring has detected a new Rust supply chain malware, IronWorm, targeting developer environments and the Web3 ecosystem through malicious npm packages. Attack activities include credential theft, harvesting wallet mnemonics and passwords, GitHub repository tampering, distribution of malicious packages, leakage of CI/CD secrets, Tor-based command-and-control, and eBPF rootkit stealth. Security teams should review commit histories, suspicious branches, unexpected build hooks, and automated identity commits.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
