← Radar

Incident case file

Sign in to watch

IronWorm — Rust-Based npm Supply Chain Infostealer Targets Web3 / Crypto Developers

Incident date June 4, 2026

1 views

ActivenpmGitHubSupply Chain / MalwareCluster: IRONWORM-NPM-2026-06

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: npm account: asteroiddao (GitHub org: asteroid-dao) | Attacker ETH operator wallet hardcoded in malware: 0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6 (confirmed empty — no funds extracted to this address) | Git commits signed under fake author 'claude' (claude@users.noreply.github.com) with backdated timestamps | C2 endpoint: /api/agent on Tor hidden service

Funds moved to: No crypto funds confirmed stolen — operator wallet 0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6 is empty. Attack designed to steal credentials (OpenAI, AWS, Anthropic, npm tokens, SSH keys, wallet seeds including Exodus wallet) and exfiltrate to C2 via Tor. Monetary impact: MISSING — impossible to quantify without victim disclosure. Cleanup incomplete as of reporting date.
36 npm packages infected across asteroid-dao organization | 9 GitHub organizations compromised | 57 commits backdated to obscure timeline | 32,177 combined downloads at time of discovery | Malware targets: 86 environment variables + 20 credential files including Exodus wallet, OpenAI keys, AWS keys, Anthropic keys, npm tokens, SSH keys, GitHub tokens, browser session data | Delivery: hidden binary in tools/setup directory within infected packages | Persistence: rootkit eBPF to evade detection |

Timeline: June 4, 2026 — JFrog Security Research and OX Security publish coordinated disclosure of IronWorm, a Rust-based infostealer malware embedded in 36 npm packages published under the asteroid-dao GitHub organization (npm account: asteroiddao). The malware is concealed in a binary within the tools/setup directory of each infected package. June 4, 2026 — Technical details published: IronWorm targets 86 environment variables and 20 specific credential files (Exodus wallet data, OpenAI/AWS/Anthropic API keys, npm tokens, SSH private keys, GitHub tokens, browser sessions). It uses a rootkit eBPF component for stealth, communicates with a C2 server via Tor at /api/agent endpoint, and self-propagates by abusing npm's Trusted Publishing workflow to republish infected packages. June 4, 2026 — Git forensics reveals 57 commits backdated by the attacker to disguise the timeline of compromise. Commits are attributed to a fake author 'claude' (claude@users.noreply.github.com). The hardcoded ETH operator wallet (0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6) is confirmed empty — either the exfiltration is via credentials rather than direct crypto drain, or the attack was detected before monetization. June 4, 2026 — BleepingComputer and The Hacker News amplify the disclosure. SlowMist recommends immediate credential rotation for any developer who installed affected packages. OX Security notes the attack was detected early before spreading to higher-traffic packages. Post June 4, 2026 — Cleanup ongoing. npm packages taken down. A concurrent but separate 'Miasma/binding.gyp' supply chain attack is identified by Endor Labs and StepSecurity in the same timeframe. No crypto losses confirmed as of reporting date.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)