Incident case file
Sign in to watchIronWorm — Rust-Based npm Supply Chain Infostealer Targets Web3 / Crypto Developers
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: npm account: asteroiddao (GitHub org: asteroid-dao) | Attacker ETH operator wallet hardcoded in malware: 0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6 (confirmed empty — no funds extracted to this address) | Git commits signed under fake author 'claude' (claude@users.noreply.github.com) with backdated timestamps | C2 endpoint: /api/agent on Tor hidden service
Timeline: June 4, 2026 — JFrog Security Research and OX Security publish coordinated disclosure of IronWorm, a Rust-based infostealer malware embedded in 36 npm packages published under the asteroid-dao GitHub organization (npm account: asteroiddao). The malware is concealed in a binary within the tools/setup directory of each infected package. June 4, 2026 — Technical details published: IronWorm targets 86 environment variables and 20 specific credential files (Exodus wallet data, OpenAI/AWS/Anthropic API keys, npm tokens, SSH private keys, GitHub tokens, browser sessions). It uses a rootkit eBPF component for stealth, communicates with a C2 server via Tor at /api/agent endpoint, and self-propagates by abusing npm's Trusted Publishing workflow to republish infected packages. June 4, 2026 — Git forensics reveals 57 commits backdated by the attacker to disguise the timeline of compromise. Commits are attributed to a fake author 'claude' (claude@users.noreply.github.com). The hardcoded ETH operator wallet (0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6) is confirmed empty — either the exfiltration is via credentials rather than direct crypto drain, or the attack was detected before monetization. June 4, 2026 — BleepingComputer and The Hacker News amplify the disclosure. SlowMist recommends immediate credential rotation for any developer who installed affected packages. OX Security notes the attack was detected early before spreading to higher-traffic packages. Post June 4, 2026 — Cleanup ongoing. npm packages taken down. A concurrent but separate 'Miasma/binding.gyp' supply chain attack is identified by Endor Labs and StepSecurity in the same timeframe. No crypto losses confirmed as of reporting date.
Sources and coverage
- Articleox.securityhttps://www.ox.security/blog/ironworm-supply-chain-malware-hits-npm/
- Articlebleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/
- Articlethehackernews.comhttps://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html
- Articlecybersecuritynews.comhttps://cybersecuritynews.com/ironworm-supply-chain-attack-uses-malicious-npm-packages/
- Articleblog.rankiteo.comhttps://blog.rankiteo.com/gitexonpm1780604646-exodus-npm-github-cyber-attack-june-2026/
- Articleit.slashdot.orghttps://it.slashdot.org/story/26/06/04/1948205/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)