IronWorm npm Supply Chain Attack
Summary
IronWorm is a Rust-based self-propagating malware campaign that compromised 36–37 npm packages in early June 2026 by exploiting a hijacked npm account ('asteroiddao') linked to the Arweave/WeaveDB ecosystem. The implant deploys an eBPF kernel rootkit, communicates over Tor, and includes a dedicated module targeting Exodus desktop wallet seed phrases and passwords. It self-replicates by abusing npm's Trusted Publishing flow and stolen GitHub Actions credentials to push backdated trojanized commits across at least nine GitHub organizations, making it one of the most technically sophisticated crypto-targeting supply chain attacks publicly documented to date.
Connected Entities
1 entities · 10 linked investigationsCommunity submissions
- Under reviewincriminatingWayback pending6/26/2026, 10:08:37 PM
“IronWorm (June 4, 2026, 36 npm packages) is part of a cluster of simultaneous npm supply-chain attacks in June 2026: Miasma hit 32+ RedHat packages (~80K weekly downloads, derived from TeamPCP's Mini Shai-Hulud); Node-gyp Supply Chain Compromise hit 57 packages with auto-trigger on npm install; and Mastra (140+ packages, North Korean APT Sapphire Sleet) targeted 160+ crypto browser extensions. IronWorm itself is Rust-written, hides behind eBPF rootkit, and communicates over Tor.”
— avoid-scout
Timeline(7 events)
2026-05-14
Separate node-ipc maintainer account compromise reported, part of the broader threat landscape targeting npm maintainers.
Cryptopolitan2026-05-01
Mini Shai-Hulud variant discovered, described as a precursor to IronWorm within the same malware family.
CryptoTimes2026-06-04
IronWorm publicly disclosed following SlowMist alert; malicious npm package versions detected under the 'asteroiddao' account targeting the Arweave/WeaveDB ecosystem.
CryptoTimes / BleepingComputer2026-06-04
Malicious npm package versions (36–37 packages) marked as deprecated within approximately one day of publication.
Cryptopolitan2026-06-05
JFrog Security Research publishes full technical analysis of IronWorm, naming it as 'Shai-Hulud's rustier cousin,' detailing eBPF rootkit, Tor C2, Trusted Publishing abuse, and hardcoded operator wallet recovery phrase.
JFrog Security Research2026-06-05
BleepingComputer and The Hacker News publish coverage; The Hacker News also reports the concurrent Miasma worm variant in the same npm attack wave.
BleepingComputer / The Hacker News2026-06-05
57 backdated malicious commits removed from the nine affected GitHub organizations, though some remain visible afterward.
JFrog Security ResearchDecision Log
- hash: A9w9S6yL8cQYSUZemzWYiKmwEUw9XMLQWdQ4NVy7gg8C
This investigation is cryptographically anchored to the Solana blockchain (1 event). 8 of 8 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/18/2026, 5:03:33 PM
last updated: 7/27/2026, 6:38:38 AM
avoid.net — verified advice for a post-truth world