SlowMist Detects New Rust Supply Chain Malware ‘IronWorm’ Targeting Web3 Developer Environments

SlowMist Detects New Rust Supply Chain Malware ‘IronWorm’ Targeting Web3 Developer Environments

N
News Editor
2026-06-04 06:50:57
SlowMist threat intelligence has detected a new Rust-based supply chain malware named IronWorm, which actively attacks developer environments through malicious npm packages, aiming at the Web3 and crypto ecosystem. The malware can steal credentials, wallet seed phrases, and more. Security teams are advised to audit repositories and rotate keys immediately.
SlowMistIronWormsupply chain attackmalwareWeb3 security

According to a post by SlowMist on X, its threat intelligence system has detected a new Rust-based supply chain malware campaign called IronWorm. The malware actively targets developer environments via malicious npm packages, with a focus on the Web3 and cryptocurrency ecosystem. The threat was discovered and analyzed by JFrogSecurity, raising serious concerns within the security community.

IronWorm’s capabilities include credential theft, wallet seed phrase and password hijacking, GitHub repository tampering, malicious package publication, CI/CD secret theft, Tor-based command and control, and stealthy persistence through an eBPF rootkit. These techniques enable long-term infiltration and pose a direct risk to development pipelines and digital assets.

Attack Vectors and Scope

The malware spreads through tainted npm dependencies—a common tool for JavaScript developers. Once a compromised package is introduced into a project, attackers can pivot into CI/CD pipelines, alter code repositories, or plant backdoors. Given the heavy reliance of Web3 projects on npm for smart contract development and frontend builds, such supply chain attacks carry outsized impact. Beyond stealing private keys and mnemonics, malicious actors can inject rogue smart contracts, leading to user asset losses.

Mitigation Steps Recommended by SlowMist

SlowMist urges security teams to conduct deep repository audits: inspect previously reverted commits, suspicious branches, unusual build hooks, and commits attributed to automated identities like claude, dependabot, renovate, or github-actions. Affected package versions should be removed or deprecated, clean versions released, and all exposed secrets and tokens rotated. Additionally, GitHub Actions build artifacts must be reviewed, and any potentially compromised developer or CI machines should be rebuilt from clean images. These steps can break the attack chain and reduce persistence risk.

This malware campaign underscores the critical importance of supply chain security in Web3. Due to the complexity of modern development environments, continuous dependency auditing and behavioral monitoring become key defensive layers.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.