• bitcoinBitcoin (BTC) $ 63,398.00
  • ethereumEthereum (ETH) $ 1,671.24
  • tetherTether (USDT) $ 0.998617
  • bnbBNB (BNB) $ 602.36
  • usd-coinUSDC (USDC) $ 0.999780
  • xrpXRP (XRP) $ 1.14
  • solanaSolana (SOL) $ 66.81
  • tronTRON (TRX) $ 0.315826
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.086276
  • hyperliquidHyperliquid (HYPE) $ 58.99
  • usdsUSDS (USDS) $ 0.999472
  • leo-tokenLEO Token (LEO) $ 9.50
  • rainRain (RAIN) $ 0.013238
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 433.14
  • moneroMonero (XMR) $ 370.42
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.198379
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • canton-networkCanton (CC) $ 0.166001
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • cardanoCardano (ADA) $ 0.171005
  • whitebitWhiteBIT Coin (WBT) $ 51.91
  • chainlinkChainlink (LINK) $ 7.88
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • the-open-networkToncoin (TON) $ 1.73
  • ethena-usdeEthena USDe (USDE) $ 0.999008
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.998030
  • daiDai (DAI) $ 0.999822
  • bitcoin-cashBitcoin Cash (BCH) $ 204.65
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 2.97
  • hedera-hashgraphHedera (HBAR) $ 0.079997
  • litecoinLitecoin (LTC) $ 42.56
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.756575
  • labLAB (LAB) $ 9.58
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • usdt0USDT0 (USDT0) $ 0.998824
  • avalanche-2Avalanche (AVAX) $ 6.65
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • paypal-usdPayPal USD (PYUSD) $ 0.999374
  • nearNEAR Protocol (NEAR) $ 2.08
  • crypto-com-chainCronos (CRO) $ 0.059895
  • global-dollarGlobal Dollar (USDG) $ 0.999768
  • tether-goldTether Gold (XAUT) $ 4,180.88
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • audieraAudiera (BEAT) $ 8.66
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bittensorBittensor (TAO) $ 213.47
  • pax-goldPAX Gold (PAXG) $ 4,192.88
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.058847
  • mantleMantle (MNT) $ 0.541580
  • ondo-financeOndo (ONDO) $ 0.365387
  • worldcoin-wldWorldcoin (WLD) $ 0.501410
  • aster-2Aster (ASTER) $ 0.629067
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • ripple-usdRipple USD (RLUSD) $ 0.999974
  • polkadotPolkadot (DOT) $ 0.950151
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • uniswapUniswap (UNI) $ 2.51
  • okbOKB (OKB) $ 72.17
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.994530
  • pi-networkPi Network (PI) $ 0.127156
  • skySky (SKY) $ 0.056829
  • usddUSDD (USDD) $ 0.998694
  • bfusdBFUSD (BFUSD) $ 0.998288
  • morphoMorpho (MORPHO) $ 1.97
  • internet-computerInternet Computer (ICP) $ 2.27
  • bitget-tokenBitget Token (BGB) $ 1.77
  • pepePepe (PEPE) $ 0.000003
  • ethereum-classicEthereum Classic (ETC) $ 7.28
  • cosmosCosmos Hub (ATOM) $ 2.00
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • usdtbUSDtb (USDTB) $ 0.999029
  • united-stablesUnited Stables (U) $ 0.999497
  • dexeDeXe (DEXE) $ 21.23
  • quant-networkQuant (QNT) $ 68.05
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • aaveAave (AAVE) $ 64.43
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.96
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.11
  • kucoin-sharesKuCoin (KCS) $ 6.74
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.65
  • kaspaKaspa (KAS) $ 0.030946
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • nexoNEXO (NEXO) $ 0.801060
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.074531
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.033623
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.088256
  • ethenaEthena (ENA) $ 0.079443
  • velvetVelvet (VELVET) $ 1.74
  • venice-tokenVenice Token (VVV) $ 15.22
  • gatechain-tokenGate (GT) $ 6.46
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.672126
  • flare-networksFlare (FLR) $ 0.007548
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • justJUST (JST) $ 0.074424
  • xdce-crowd-saleXDC Network (XDC) $ 0.030498
  • filecoinFilecoin (FIL) $ 0.760106
  • ghoGHO (GHO) $ 0.998501
  • injective-protocolInjective (INJ) $ 5.55
  • usual-usdUsual USD (USD0) $ 0.998718
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • yldsYLDS (YLDS) $ 0.999817
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • midnight-3Midnight (NIGHT) $ 0.033067
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.160978
  • aptosAptos (APT) $ 0.650273
  • arbitrumArbitrum (ARB) $ 0.083495
  • clbtcclBTC (CLBTC) $ 76,920.00
  • hash-2Provenance Blockchain (HASH) $ 0.009606
  • a7a5A7A5 (A7A5) $ 0.013239
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.16
  • usxUSX (USX) $ 0.999395
  • pump-funPump.fun (PUMP) $ 0.001459
  • true-usdTrueUSD (TUSD) $ 0.998320
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.54
  • adi-tokenADI (ADI) $ 3.73
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.32
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 35.51
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • euro-coinEURC (EURC) $ 1.16
  • kite-2Kite (KITE) $ 0.188123
  • beldexBeldex (BDX) $ 0.056473
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.192524
  • vechainVeChain (VET) $ 0.004945
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006768
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • official-trumpOfficial Trump (TRUMP) $ 1.75
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • apxusdapxUSD (APXUSD) $ 0.963622
  • hastra-primePRIME (PRIME) $ 1.04
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • curve-dao-tokenCurve DAO (CRV) $ 0.260763
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.597364
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000071
  • bonkBonk (BONK) $ 0.000004
  • lighterLighter (LIT) $ 1.55
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • the9bitThe9bit (9BIT) $ 0.044142
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • siren-2Siren (SIREN) $ 0.498710
  • ethgas-2ETHGas (GWEI) $ 0.165427
  • humanityHumanity (H) $ 0.192443
  • blockstackStacks (STX) $ 0.183938
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996974
  • sei-networkSei (SEI) $ 0.049904
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • aerodrome-financeAerodrome Finance (AERO) $ 0.351391
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • unibaseUnibase (UB) $ 0.128336
  • sun-tokenSun Token (SUN) $ 0.016709
  • kinesis-goldKinesis Gold (KAU) $ 130.69
  • spx6900SPX6900 (SPX) $ 0.325097
  • celestiaCelestia (TIA) $ 0.324525
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • pyth-networkPyth Network (PYTH) $ 0.037688
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • chilizChiliz (CHZ) $ 0.027526
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • skyaiSkyAI (SKYAI) $ 0.274143
  • ether-fiEther.fi (ETHFI) $ 0.305554
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • apenftAINFT (NFT) $ 0.00000027
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • gnosisGnosis (GNO) $ 97.09
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • jito-governance-tokenJito (JTO) $ 0.530235
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • kinesis-silverKinesis Silver (KAG) $ 67.23
  • monadMonad (MON) $ 0.021453
  • tezosTezos (XTZ) $ 0.230809
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • royal-dollarRoyal Dollar (RUSD) $ 0.999628

IronWorm malware plants rootkit in Arweave ecosystem npm libraries

0 0


Attackers planted an infostealer inside 36 npm packages linked to the Arweave ecosystem. It targeted developer credentials, SSH keys, and Exodus crypto wallet files. Security firm JFrog traced the attack back to a compromised maintainer account.

The malware is called IronWorm, and its built using Rust. It activates the moment a developer installs an npm package. Once running, it scans through the infected computer for 86 environment variables and 20 credential files, as JFrog’s research team found. It goes after AWS tokens, Anthropic and OpenAI API keys, npm authentication credentials, and crypto wallet data.

Arweave project packages carry hidden Rust malware

Attackers comproimised an npm account called “asteroiddao,” which belongs to the asteroid-dao GitHub group, part of the Arweave/WeaveDB decentralized database project.

All packages associated with the “asteroiddao” account were republished within a short time, with each new version containing a 976 KB Linux file located in a tools/ directory.

The file was set to run automatically through a preinstall hook in package.json, meaning it launched before npm even began installing anything. All a victim had to do was run npm install.

JFrog’s team pulled the file apart and found it had been packed in a way designed to fool standard unpacking tools. Inside was a large Rust program that kept its strings encrypted individually, with each one locked separately, making analysis much harder.

When those strings were finally decoded, they revealed GitHub API endpoints, paths to credential files, fake bot accounts linked to real GitHub user IDs, and templates for injecting malicious code into other package registries.

A screenshot showing infected npm packages related to the Arweave ecosystem. Source: Jfrog.

Stolen GitHub tokens let malware push commits and infect more repos

After harvesting credentials, IronWorm used them to push commits into repositories the victim could access. Those commits planted the same malicious binary into other packages, which could then be published to npm and compromise the next developer in the chain.

JFrog found 57 backdated malicious commits across nine GitHub organizations. The commits used the author name “claude” with the email claude@users.noreply.github.com. Timestamps were forged to match each repository’s most recent legitimate commit. One appeared to date back 13 years, though GitHub Actions logs confirmed all pushes happened within a few days of discovery.

The affected organizations included asteroid-dao, weavedb, ArweaveOasis, and several personal accounts associated with the developer “ocrybit.”

IronWorm also deployed an eBPF kernel rootkit to hide on infected machines. Communications to its operator routed through the Tor network. The Rust compiler left the rootkit’s source code in the binary, an operational mistake that made analysis easier.

One oddity is that the operator hardcoded their own cryptocurrency wallet recovery phrase into the malware. JFrog concluded this was a safeguard to prevent the stealer from exfiltrating the attacker’s own credentials during testing.

Malware attacks keep hitting npm

Application security firm Ox Security said that the attack was caught early, before it could spread to more packages on npm.

The malicious versions were marked as deprecated within a day and most of the backdated commits were removed from GitHub shortly after.

On May 14, hackers exploited an inactive maintainer account for node-ipc, a package with more than 822,000 weekly downloads. The exploit was accomplished by re-registering the maintainer’s expired email domain and resetting the npm password. Three compromised variants had credential stealing payloads aimed at over 90 categories of developer secrets.

Security firms Endor Labs and StepSecurity identified a concurrent but distinct attack using JavaScript-based malware called binding.gyp, which performed similar registry poisoning and GitHub Actions infection during the same timeframe.

Developers who installed any of the affected WeaveDB packages should rotate all credentials, check lock files for unexpected version changes, and enable two-factor authentication on npm and GitHub accounts.



Source link

Leave A Reply

Your email address will not be published.