IronWorm: The Rust-Powered Malware Campaign That Infiltrated the Arweave Ecosystem and Threatens the Software Supply Chain
The open-source ecosystem has long been one of the greatest strengths of modern software development. Millions of developers rely on package repositories such as npm to accelerate innovation, build applications faster, and collaborate across decentralized communities. However, that same openness has increasingly become a prime target for sophisticated cybercriminals. A recent attack involving the Arweave ecosystem demonstrates just how dangerous software supply chain compromises have become. Security researchers uncovered a highly sophisticated malware campaign known as IronWorm , which infiltrated dozens of npm packages connected to the Arweave and WeaveDB ecosystem. The attack targeted developer credentials, cloud access tokens, cryptocurrency wallets, and source code repositories, highlighting a growing threat facing blockchain infrastructure and open-source software projects worldwide. A Supply Chain Attack Hidden Inside Trusted Packages The campaign began when attackers succe...