Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » IronWorm Malware Targets Crypto Developers Through Supply Chains

IronWorm Malware Targets Crypto Developers Through Supply Chains

Sophisticated Infostealer Spreads Through Trusted Software Packages

Kelly Cromley by Kelly Cromley
Jun 5, 2026
in Market News, News
Reading Time: 3 mins read
0
slowmist

Cybersecurity researchers have uncovered a new malware campaign aimed at the cryptocurrency development ecosystem, raising concerns about the security of software supply chains used by developers. The malware, known as IronWorm, has been identified as a sophisticated Rust-based infostealer capable of bypassing traditional code review and security auditing processes.

According to findings shared by security firms SlowMist and JFrog Security Research, IronWorm is designed to collect highly sensitive information from infected systems. The malware reportedly targets cryptocurrency wallet credentials, cloud service access keys, GitHub authentication tokens, and various development-related login credentials. Researchers indicated that the threat is particularly dangerous because it spreads through trusted software distribution channels, allowing a single compromised package to affect numerous projects and developers.

Researchers reported that IronWorm not only steals credentials but can also modify software repositories and republish compromised packages, enabling the malware to spread autonomously across development ecosystems.

This self-propagating behavior creates a cycle in which compromised developer accounts are used to distribute additional malicious packages. As a result, the malware can expand its reach across open-source projects and Web3 applications without requiring direct interaction from attackers.

Malicious npm Packages Used as Delivery Method

JFrog’s investigation revealed that the malware was distributed through npm packages associated with an account identified as asteroiddao. Researchers explained that attackers uploaded packages that appeared legitimate while secretly embedding Linux-based malware within installation files.

The infection process was triggered automatically through npm preinstall scripts. This mechanism meant that developers could unknowingly compromise their systems simply by installing what appeared to be a normal software package. One package that attracted attention during the investigation was [email protected], which reportedly displayed suspicious behavior during execution.

Further analysis revealed multiple techniques intended to hinder detection and reverse engineering efforts. Investigators found encrypted strings, a customized version of the UPX packing tool, and complex Rust code structures designed to conceal the malware’s functionality. After unpacking the code, researchers discovered modules connected to GitHub APIs, credential harvesting activities, and mechanisms that supported self-replication.

Credential Theft and Stealth Features Raise Concerns

Researchers stated that IronWorm aggressively targets credentials across a broad range of development environments. The malware reportedly seeks access to cloud platforms such as AWS, container technologies including Kubernetes and Docker, artificial intelligence development environments, and cryptocurrency wallets.

🚨 SlowMist TI Alert 🚨

A new Rust-based supply-chain malware campaign, IronWorm, actively targeting developer environments and Web3/crypto ecosystems via malicious npm packages.

Potential attacker actions include credential theft, wallet seed and password theft, GitHub… pic.twitter.com/3ZgDHmrIuw

— SlowMist (@SlowMist_Team) June 4, 2026


Investigators found that the malware specifically targets Exodus wallet users by attempting to capture passwords and recovery phrases as they are entered.

JFrog also discovered 57 fraudulent commits distributed across nine organizations. These changes were disguised as routine maintenance updates and attributed to trusted automated identities such as claude, dependabot, and github-actions. This tactic reportedly helped malicious activity blend in with legitimate software development processes.

To maintain persistence and avoid detection, IronWorm deploys an eBPF rootkit capable of hiding active processes and network communications. Researchers further noted that the malware uses Tor-based infrastructure for command-and-control communications and data exfiltration, making its network traffic significantly harder to trace.

Despite its advanced capabilities, investigators identified operational mistakes by the attackers. Debugging information was reportedly left within the malware, and one hardcoded wallet recovery phrase was exposed, potentially revealing information about the campaign operators.

Growing Trend of Supply-Chain Attacks

The discovery of IronWorm highlights the growing threat of supply-chain attacks, where malicious actors compromise trusted software packages to infiltrate cryptocurrency, AI, cybersecurity, and open-source development environments.

The campaign follows several similar incidents reported throughout the year. In May, researchers identified the TrapDoor campaign, which leveraged malicious packages across npm, PyPI, and Crates.io to target developers working in cryptocurrency, decentralized finance, artificial intelligence, and cybersecurity sectors.

More recently, SlowMist warned about another malware strain known as Mini Shai-Hulud, which reportedly infected more than 170 JavaScript packages. Security experts noted that the malware spread through widely used open-source libraries, increasing potential exposure across the software ecosystem. Earlier this year, attackers also compromised Axios package releases after obtaining access to publishing credentials, further underscoring the risks facing software supply chains.

Previous Post

LBank Becomes ENI Super Node to Expand Web3 Infrastructure

Next Post

PUNKVISM and ChainArt Join Forces for NFT Ticketing Expansion

Related Posts

4bsc ai

Anome Protocol Integrates AI to Simplify Web3 Operations

by Kelly Cromley
Jun 5, 2026
0

Anome Protocol, a decentralized platform that combines decentralized finance, social engagement, and blockchain gaming services, has entered into a strategic...

Aptos

Aptos Launches Stablecoin Corridor Linking UAE and Africa

by Kelly Cromley
Jun 5, 2026
0

Aptos Foundation, HashKey MENA, and African payments platform Daya have partnered to establish a stablecoin-powered payment corridor connecting the Middle...

Visa

Visa and Brale Test Private Stablecoin Settlement Network

by Kelly Cromley
Jun 5, 2026
0

Visa has launched a proof-of-concept initiative in partnership with Brale, a provider of stablecoin infrastructure, to explore private blockchain-based settlement...

m3 dao

M3 DAO and FISH Partner to Expand Web3 Gaming Adoption

by Kelly Cromley
Jun 5, 2026
0

M3 DAO, a community-driven Web3 network, has announced a strategic partnership with FISH, a Web3 gaming ecosystem focused on competitive...

Cosmos

Cosmos Joins UNDP Blockchain Advisory Group Initiative

by Kelly Cromley
Jun 5, 2026
0

Cosmos has announced its participation in the United Nations Development Programme’s (UNDP) Blockchain Advisory Group, a collaborative initiative that brings...

TRON

TRON DAO Unveils Dune MCP for AI-Powered Blockchain Analytics

by Kelly Cromley
Jun 5, 2026
0

TRON DAO has announced the launch of Dune MCP, a new solution designed to provide natural language access to blockchain...

Next Post
punkvism

PUNKVISM and ChainArt Join Forces for NFT Ticketing Expansion

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

4bsc ai
Market News

Anome Protocol Integrates AI to Simplify Web3 Operations

by Kelly Cromley
Jun 5, 2026
Aptos
Market News

Aptos Launches Stablecoin Corridor Linking UAE and Africa

by Kelly Cromley
Jun 5, 2026
Visa
Market News

Visa and Brale Test Private Stablecoin Settlement Network

by Kelly Cromley
Jun 5, 2026
m3 dao
Market News

M3 DAO and FISH Partner to Expand Web3 Gaming Adoption

by Kelly Cromley
Jun 5, 2026
Cosmos
Market News

Cosmos Joins UNDP Blockchain Advisory Group Initiative

by Kelly Cromley
Jun 5, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.