Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
IronWorm Threat Exploits npm to Steal Developer Data

IronWorm Threat Exploits npm to Steal Developer Data

Posted on June 4, 2026 By CWS

A sophisticated malware campaign known as IronWorm has emerged, targeting software developers through compromised npm packages designed to steal sensitive information, such as credentials, API keys, and cryptocurrency wallet recovery phrases.

The Mechanics of IronWorm

IronWorm infiltrates trusted developer workflows, making it a significant supply-chain threat. The malware is embedded within npm packages that appear legitimate at first glance. Attackers republish these packages with a concealed Linux binary, which activates automatically when a developer runs ‘npm install’. No additional user interaction is required, making the attack particularly insidious.

Security specialists from JFrog revealed in a report that IronWorm is a custom-built, Rust-based infostealer. It extracts every secret available on a developer’s system, using a kernel-level rootkit to remain undetected, while communicating with its operator via the Tor network.

Impact on Developers and the Software Supply Chain

The campaign primarily targets software developers, with a focus on those involved in cryptocurrency and web3 projects. IronWorm aggressively uses stolen credentials to push backdated commits into victims’ GitHub repositories. These commits contain malware that infects other packages, perpetuating the threat as these packages are published on npm and installed by other developers.

Researchers have identified 57 backdated malicious commits across nine GitHub organizations. Some commits are made to appear years old by copying timestamps from legitimate repository commits, a tactic designed to evade detection during code reviews.

Technical Details and Countermeasures

IronWorm’s malicious binary is hidden in a directory path unlikely to be checked by developers. The binary is packed with a modified UPX tool, removing standard signatures to prevent automated unpacking. Once operational, the malware decrypts its strings individually, complicating reverse engineering efforts.

The malware scans for 86 environment variables related to cloud platforms, databases, CI/CD systems, and source control tokens. It also targets credential files like wallet configs. A module specifically targets the Exodus desktop wallet, capturing sensitive data during user interaction. Another module focuses on Kubernetes pods, accessing and dumping secrets.

IronWorm utilizes an eBPF-based rootkit to conceal its processes and network connections from monitoring tools. It manipulates kernel-level data to hide from commands like ‘ps’ and ‘top’, and blocks debugger attachments, causing potential system crashes.

Security experts advise a thorough audit of all repositories with compromised account access, checking for suspicious commits and unexpected build hooks. API keys and secrets should be rotated immediately. Malicious npm packages should be unpublished, and a security advisory issued to alert downstream users.

For more on IronWorm and other cybersecurity threats, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:credential theft, crypto theft, Cybersecurity, developer security, GitHub, IronWorm, JFrog report, Linux binary, Malware, NPM, Rootkit, Rust-based malware, supply chain attack, Tor network, Web3 security

Post navigation

Previous Post: CISA Alerts on Magento Cache Warmer Security Vulnerability
Next Post: Anthropic’s New AI Model Faces Early Security Breach

Related Posts

New Ghost-tapping Attacks Steal Customers’ Cards Linked to Services Like Apple Pay and Google Pay New Ghost-tapping Attacks Steal Customers’ Cards Linked to Services Like Apple Pay and Google Pay Cyber Security News
OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware OpenAI Banned ChatGPT Accounts Used by Chinese Hackers to Develop Malware Cyber Security News
US Sanction Key Threat Actors Linked With North Korea’s Remote IT Worker Scheme US Sanction Key Threat Actors Linked With North Korea’s Remote IT Worker Scheme Cyber Security News
Ghost CMS Vulnerability Exploited in Widespread Malware Attack Ghost CMS Vulnerability Exploited in Widespread Malware Attack Cyber Security News
6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability 6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability Cyber Security News
Google Urgently Updates Chrome to Fix Exploited Flaws Google Urgently Updates Chrome to Fix Exploited Flaws Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ASUS Fixes Critical Router Flaw Allowing Remote Attacks
  • GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards
  • Adobe Extension Vulnerability Exposes WhatsApp Chats
  • Adobe Acrobat Extension Flaw Risked WhatsApp Data Breach
  • RefluXFS Exploit Threatens Linux Systems with Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ASUS Fixes Critical Router Flaw Allowing Remote Attacks
  • GitHub Reduces Public Bug Bounty Payouts, Enhances VIP Rewards
  • Adobe Extension Vulnerability Exposes WhatsApp Chats
  • Adobe Acrobat Extension Flaw Risked WhatsApp Data Breach
  • RefluXFS Exploit Threatens Linux Systems with Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark