SlowMist: Ironworm malware attacks the web3 ecosystem via npm packages
2026-06-04 14:52:17
According to CoinWorld, SlowMist has detected a new type of Rust supply chain malware, Ironworm, which is using malicious npm packages to attack developer environments and the web3 ecosystem. Attacks include credential theft, wallet mnemonic phrase and password theft, GitHub repository tampering, malicious package distribution, CI/CD confidentiality leaks, Tor-based command control, and eBPF rootkit stealth. Security teams need to review backtracking commits, suspicious branches, accidental build hooks, and automated identity submissions.
Bullish 0
Bearish 0
Source:Internet
This content is for market information only and does not constitute investment advice.