Check your Exodus wallet and cloud credentials; over 30 packages have been poisoned, and the attack happened during the pre-installation phase.

View Original
CoinNetwork
Aikido Security: New "ironworm" supply chain attack affects over 30 npm packages
Aikido Security disclosed a supply chain attack called ironworm, affecting over 30 npm packages of AsteroidDAO. Malicious Rust binaries execute during the pre-installation phase, capable of scanning environment variables and credentials, targeting AWS, GCP, Vault, npm, and AI keys, and attempting to attack Exodus wallets. It uses eBPF rootkit for hiding, reconnects via Tor, propagates itself through the npm trusted publishing OIDC mechanism, and disguises itself as submissions like Claude to cover tracks.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned