IronWorm is a Rust-based self-propagating supply-chain malware family targeting software developers through trojanized npm packages and compromised publishing workflows. It is best characterized as an infostealer with worm-like propagation features: after execution, it harvests high-value developer, cloud, CI/CD, source-control, package-registry, messaging, Kubernetes, Vault, AI-service, and cryptocurrency secrets from infected environments, then reuses stolen access to compromise additional repositories and publish further malicious package updates.
The campaign has been associated with compromises in the npm ecosystem, including activity affecting the Arweave and WeaveDB developer ecosystem. Initial execution has been observed via malicious npm lifecycle hooks and package-embedded native binaries. IronWorm has also been reported using compromised GitHub access to insert deceptive backdated commits across multiple organizations and to tamper with build and publishing workflows. In CI environments, it can abuse npm Trusted Publishing by leveraging short-lived OIDC-derived publish credentials, allowing propagation without relying on stored npm tokens.
IronWorm primarily targets Linux developer and build environments, but reporting also describes cross-platform payload delivery in some related package compromises attributed to an evolved IronWorm variant, including Windows and macOS payloads. On Linux, the malware includes an eBPF-based rootkit component used for stealth, including hiding processes and network activity and impeding analysis. It also communicates with operators over Tor and supports post-compromise tasking such as secret upload, file delivery, and remote shell functionality.
Observed collection behavior includes theft of environment variables, credential files, SSH keys, browser and collaboration-platform data, cloud credentials, package publishing tokens, and cryptocurrency wallet material. Specialized modules have been reported for targeting Exodus wallet data and for harvesting Kubernetes service-account tokens and accessible secrets, with follow-on attempts to access Vault. Persistence and privilege-related behaviors have also been reported in some evolved variants.
IronWorm has been compared to Shai-Hulud and Mini Shai-Hulud because of its self-replication and software-supply-chain focus, but direct attribution remains unconfirmed. The malware represents a notable evolution in developer-focused intrusion tradecraft by combining credential theft, Linux kernel-level stealth, Tor-based command and control, and autonomous propagation through trusted software distribution channels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Специалисты компании JFrog обнаружили инфостилер IronWorm, который успел заразить 36 пакетов и был нацелен на кражу секретов разработчиков, учетных данных для облачных сервисов и ключей доступа.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The code searches compromised systems for npm authentication tokens, validates the stolen credentials, identifies valuable packages...
Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential.
The incident transformed a trusted development dependency into a malware delivery mechanism... JFrog also reported that the malware... injects malicious components into package archives, and attempts to publish trojanized versions directly to the npm registry.
The malicious activity has been traced back to a compromised npm account named "asteroiddao," which has been found to publish package versions containing the Rust ELF binary that's executed via a preinstall hook.
Security researchers first identified version 8.14.0 as the initial compromised release after discovering that it introduced a previously undocumented npm "preinstall" lifecycle hook.
Technical analysis showed the package concealed separate native payloads for Linux, Windows, and macOS inside an obfuscated container embedded within the package.
A lightweight loader selected the appropriate binary for the host operating system, wrote it to a temporary directory under a randomized filename... and launched it as a background process with minimal user visibility.
The code searches compromised systems for npm authentication tokens, validates the stolen credentials, identifies valuable packages...
Windows and macOS variants incorporated persistence mechanisms designed to survive system reboots...
This component works as a Linux kernel rootkit that helps to hide the malware’s processes and network activity.
The code searches compromised systems for npm authentication tokens, validates the stolen credentials...
Investigators found code targeting... browser-stored passwords and cookies...
Малварь нацелена на кражу... SSH-ключи, конфигурации хранилищ и файлы криптовалютных кошельков Exodus.
Investigators found code targeting cloud credentials associated with AWS, Microsoft Azure, and Google Cloud, browser-stored passwords and cookies, cryptocurrency wallets, Bitwarden vault data...
Investigators found code targeting... browser-stored passwords and cookies...
The malware was also found to accept commands for uploading secrets, dropping files and running remote shells through a Tor-based command-and-control (C2) setup.
IronWorm написан на Rust, взаимодействует со своими операторами через Tor...
The malware was also found to accept commands for uploading secrets, dropping files and running remote shells through a Tor-based command-and-control (C2) setup.
The malware was also found to accept commands for uploading secrets... through a Tor-based command-and-control (C2) setup. ... the attacks share similarities including self-propagation and exfiltration of data to GitHub.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rust-based malware targeting npm supply chains, using an eBPF rootkit, Tor communications, and self-propagation via stolen npm and GitHub credentials to trojanize maintained packages and plant backdated commits.
A Rust-based infostealer delivered via compromised Jscrambler npm package releases. It steals cloud credentials, browser passwords and cookies, cryptocurrency wallets, Bitwarden data, communication app data, developer secrets, VPN configurations, Tor-related files, and configuration files for AI-assisted development tools. It also includes persistence on Windows and macOS, encrypted C2 communications, Linux eBPF-related functionality under investigation, and attempts self-propagation by stealing npm tokens and publishing trojanized packages to the npm registry.
A recent npm attack wave involving a Rust-based credential stealer and an eBPF rootkit, noted as similar to Mini Shai-Hulud.
A previously referenced supply-chain malware campaign noted only for similarity in technique: use of a preinstall script to execute an embedded binary from a package.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.