Skip to content
SlowMist Discovers IronWorm Malware Targeting the Web3 Ecosystem via npm Packages

SlowMist Discovers IronWorm Malware Targeting the Web3 Ecosystem via npm Packages

Kucoin June 4, 2026

SlowMist monitoring has detected a new Rust supply chain malware, IronWorm, targeting developer environments and the Web3 ecosystem through malicious npm packages. Attack activities include credential theft, harvesting wallet mnemonics and passwords, GitHub repository tampering, distribution of malicious packages, leakage of CI/CD secrets, Tor-based command-and-control, and eBPF rootkit stealth. Security teams should review commit histories, suspicious branches, unexpected build hooks, and automated identity commits.