Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Attackers trojanized Arweave’s WeaveDB npm package to deploy malware

Attackers trojanized Arweave’s WeaveDB npm package to deploy malware

CryptopolitanCryptopolitan2026/06/06 04:39
By:Cryptopolitan

Attackers planted an infostealer inside 36 npm packages linked to the Arweave ecosystem. It targeted developer credentials, SSH keys, and Exodus crypto wallet files. Security firm JFrog traced the attack back to a compromised maintainer account.

The malware is called IronWorm, and its built using Rust. It activates the moment a developer installs an npm package. Once running, it scans through the infected computer for 86 environment variables and 20 credential files, as JFrog’s team found. It goes after AWS tokens, Anthropic and OpenAI API keys, npm authentication credentials, and crypto wallet data.

Arweave project packages carry hidden Rust malware

Attackers  comproimised an npm account called “asteroiddao,” which belongs to the asteroid-dao GitHub group, part of the Arweave/WeaveDB decentralized database project.

All packages associated with the “asteroiddao” account were republished within a short time, with each new version containing a 976 KB Linux file located in a tools/ directory.

The file was set to run automatically through a preinstall hook in package.json, meaning it launched before npm even began installing anything. All a victim had to do was run npm install.

JFrog’s team pulled the file apart and found it had been packed in a way designed to fool standard unpacking tools. Inside was a large Rust program that kept its strings encrypted individually, with each one locked separately, making analysis much harder.

When those strings were finally decoded, they revealed GitHub API endpoints, paths to credential files, fake bot accounts linked to real GitHub user IDs, and templates for injecting malicious code into other package registries.

A screenshot showing infected npm packages related to the Arweave ecosystem. Source: Jfrog.

Stolen GitHub tokens let malware push commits and infect more repos

After harvesting credentials, IronWorm used them to push commits into repositories the victim could access. Those commits planted the same malicious binary into other packages, which could then be published to npm and compromise the next developer in the chain.

JFrog found 57 backdated malicious commits across nine organizations. The commits used the author name “claude” with the email [email protected]. Timestamps were forged to match each repository’s most recent legitimate commit. One appeared to date back 13 years, though GitHub Actions logs confirmed all pushes happened within a few days of discovery.

The affected organizations included asteroid-dao, weavedb, ArweaveOasis, and several personal accounts associated with the developer “ocrybit.”

IronWorm also deployed an eBPF kernel rootkit to hide on infected machines. Communications to its operator routed through the Tor network. The Rust compiler left the rootkit’s source code in the binary, an operational mistake that made analysis easier.

One oddity is that the operator hardcoded their own cryptocurrency wallet recovery phrase into the malware. JFrog concluded this was a safeguard to prevent the stealer from exfiltrating the attacker’s own credentials during testing.

Malware attacks keep hitting npm

Application security firm Ox Security said that the attack was caught early, before it could spread to more packages on npm.

The malicious versions were marked as deprecated within a day and most of the backdated commits were removed from GitHub shortly after.

On May 14, hackers exploited an inactive maintainer account for node-ipc, a package with more than 822,000 weekly downloads. The exploit was accomplished by re-registering the maintainer’s expired email domain and resetting the npm password. Three compromised variants had credential stealing payloads aimed at over 90 categories of developer secrets.

Security firms Endor Labs and StepSecurity identified a concurrent but distinct attack using JavaScript-based malware called binding.gyp, which performed similar registry poisoning and GitHub Actions infection during the same timeframe.

Developers who installed any of the affected WeaveDB packages should rotate all credentials, check lock files for unexpected version changes, and enable two-factor authentication on npm and GitHub accounts.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Updated: Delta Air Lines warns that as fuel prices hit profits, airline capacity will tighten further

Delta Airlines lowers its annual profit forecast due to an expected increase in fuel costs to $6 billion. The CEO stated that ticket prices have risen by about 20% this year, with limited passenger resistance. Analysts warn that maintaining high ticket prices in 2027 is critical for improving profitability. The article includes comments from the earnings call and analyst remarks. Rajesh Kumar Singh/Shivansh Tiwary, Reuters Chicago, October 9 - Delta Airlines (DAL.N) said on Friday that, despite strong travel demand and rising ticket prices, soaring fuel costs have forced it to cut its 2026 profit expectations by nearly a quarter. So, the airline industry may need to further limit flight growth next year to protect profitability. This warning highlights the increasingly tough challenges faced by U.S. airlines. While strong demand and restricted seat growth have allowed airlines to significantly raise ticket prices and offset higher fuel costs, aggressively increasing flights to capture more demand may intensify competition, making it harder to maintain high fares and protect profits. Based in Atlanta, Delta now expects its annual fuel expenditure to increase by about $6 billion compared to last year—about $2 billion higher than its July forecast—due to the Iran war (link) causing global jet fuel prices to spike. Airlines worldwide are preparing for a prolonged fuel shock. Michael O’Leary, CEO of Ryanair Group RYA.I, said Thursday that high jet fuel prices could persist for another 12-18 months (link), adding more pressure on airlines to raise fares and control costs. https://www.reuters.com/graphics/AUTOMATED-20261008/A4A-JET-FUEL-DAILY-1Y/xmpjwjnmbvr/chart.png “In a high-cost environment, you can’t simply grow your way out,” Delta CEO Ed Bastian said on the earnings call. He noted that the industry has already taken steps to restrict capacity, but more measures will be needed next year to improve profitability. Bastian said Delta raised ticket prices about 20% this year, and passenger resistance has been limited. He is confident that even if fuel costs eventually drop, the high fares can still be maintained. Delta lowered its adjusted annual earnings per share forecast from the July prediction of $6.50-$7.50 to $5.10-$5.60. According to LSEG data, the midpoint of the new range is below analysts’ average expectation of $5.46. Third-quarter adjusted earnings per share were $1.72, four cents below analysts’ average forecast. In midday trading, shares of Delta dropped 1.7%, United Airlines UAL.O fell 1.4%, and both American Airlines AAL.O and Southwest Airlines LUV.N were down about 1%. Delta partly shields itself from rising fuel costs by owning a refinery outside Philadelphia (link), which is expected to generate over $700 million in profits this year. Even with this buffer, the airline expects its fourth-quarter fuel price to rise from $3.61 per gallon in Q3 to $4.25 per gallon. Delta forecasts adjusted fourth-quarter earnings per share to be between $1.15-$1.65, with the $1.40 midpoint roughly matching analysts’ average expectation of $1.39. Fare increases Government data shows that in the first eight months of 2026, U.S. airlines spent $42.9 billion on fuel, an increase of $13.2 billion compared to the same period last year despite slightly reduced consumption. According to the U.S. Bureau of Labor Statistics, strong demand and limited seat growth pushed average U.S. airline ticket prices up by about 25% year-on-year between April and August. https://www.reuters.com/graphics/USA-AIRLINES/FUEL/lbpgdnbzwvq/chart.png Analysts at Melius Research said that despite surging fuel costs, Delta’s ability to raise fares helps keep second-half profits roughly stable. Still, they warn that the company’s profit margin has struggled to improve over the years. “It is critical for margin improvement to maintain or raise fares in 2027,” they wrote in their research report. With industry capacity growth expected to accelerate in Q4, this challenge will likely become even tougher. Deutsche Bank analysts expect the proportion of fuel costs recouped through revenue measures to fall in Q4 and predict full recovery won’t happen until early 2027. Bastian noted that low industry returns are another reason for limiting capacity growth. He said Delta will be cautious with its 2027 capacity plan until the fuel price outlook becomes clearer. He added that international routes may account for a larger share of Delta’s capacity expansion compared to domestic routes. Currently, Delta says its premium cabins and corporate travel business remain strong, and its economy cabin business is gradually improving. With Q4 ticket bookings already exceeding 60%, Delta expects revenue to increase about 20% year-on-year, despite limited capacity growth. Executives said early booking trends for Q1 2027 are also encouraging. (For the convenience of non-native English speakers, Reuters automatically translates its reports into several

路透社•2026/10/09 17:36

Wall Street giants to release financial reports next week: stock trading revenue expected to approach $19 billion, "everyone is a winner" may be a thing of the past

According to analyst expectations compiled by Bloomberg, the combined equity trading revenue of the five major U.S. banks in the third quarter will approach $19 billion, but fixed income trading revenue is expected to drop to its lowest point of the year, and M&A activity has also cooled. Meanwhile, AI-driven cash optimization tools may lead to deposit outflows, sparking concerns about bank stocks in the market. Analysts believe that while the profit performance of each bank may further diverge, market concerns about the impact of AI may be overblown.

华尔街见闻•2026/10/09 16:11