IronWorm Malware Targets Crypto Developers; 57 Fraudulent Commits Discovered on June 4

According to SlowMist and JFrog Security Research, IronWorm, a sophisticated Rust-based infostealer, was discovered on June 4, 2026, targeting cryptocurrency developers through malicious npm packages. The malware steals wallet credentials, GitHub authentication tokens, cloud service access keys, and development-related login credentials. Researchers found 57 fraudulent commits distributed across nine organizations, disguised as routine updates using trusted identities like dependabot and github-actions. IronWorm spreads through npm preinstall scripts and employs an eBPF rootkit for persistence, while using Tor-based infrastructure for command-and-control communications.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments