Exodus Intelligence A.I CyberSecurity Scoring
Exodus Intelligence
Company Information
Website:https://www.exodusintel.com
Employees number:45
Number of followers:3,524
NAICS:541514
Industry Type:Computer and Network Security
Homepage:exodusintel.com
Exodus Intelligence Risk Score (AI oriented)
Between 700 and 749
Exodus IntelligenceComputer and Network Security
Updated:
04/06/2026
04/06/2026
732/1000
Moderate
Ba
Exodus Intelligence Global Score (TPRM)
xxxx
Exodus IntelligenceComputer and Network Security
Score locked

Exodus IntelligenceModerate
Current Score
732Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750
Cyber Attack
04 Jun 2026 • Exodus Intelligence
Exodus, npm and GitHub: IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets
IronWorm Malware Campaign Targets Developers via Poisoned npm Packages
732
CRITICAL-18
GITEXONPM1780604646
IronWorm Malware Campaign Targets Developers via Poisoned npm Packages
A sophisticated malware campaign, dubbed IronWorm, has been discovered targeting software developers particularly those in crypto and web3 through malicious npm packages. The attack leverages compromised developer workflows to steal credentials, API keys, and cryptocurrency wallet recovery phrases, while spreading autonomously via trusted supply-chain channels.
### How the Attack Works
IronWorm infiltrates systems by hiding a Rust-based infostealer inside seemingly legitimate npm packages. When a developer runs `npm install`, the malware executes automatically, requiring no user interaction. The threat actor republished multiple npm packages from a hijacked account, embedding a hidden Linux binary in each.
Once active, IronWorm employs a kernel-level rootkit to evade detection, masking its processes and network activity from standard monitoring tools like `ps` and `top`. It communicates with its operator via the Tor network and uses obfuscation techniques, including a modified UPX packer and per-string decryption, to hinder reverse engineering.
### Credential Theft & Self-Replication
The malware aggressively harvests sensitive data, scanning for 86 environment variables (covering cloud platforms, CI/CD systems, and AI service keys) and 20+ credential file paths, including wallet configurations. A dedicated module targets the Exodus desktop wallet, capturing passwords and recovery phrases upon unlock. Another module extracts Kubernetes service account tokens from pods.
IronWorm’s most dangerous feature is its self-replicating mechanism. After stealing credentials, it uses them to push backdated malicious commits into victims’ GitHub repositories, disguising them as routine maintenance (e.g., "fix: resolve lint warnings"). These infected packages are then published to npm, creating a supply-chain loop that spreads the malware further. Researchers identified 57 backdated commits across nine GitHub organizations, some timestamped years in the past to avoid scrutiny.
### Scope & Indicators of Compromise
The campaign has impacted dozens of npm packages, including:
- `[email protected]`
- `[email protected]`
- `[email protected]`
- `[email protected]`
Malicious commits were attributed to a fake GitHub email (`[email protected]`), and the operator’s Ethereum wallet address (`0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6`) was hardcoded in the malware. The C2 endpoint (`/api/agent`) operates over Tor, and the malicious binary resides in a hidden path (`tools/setup`).
### Mitigation & Response
Security firm JFrog recommends auditing repositories for backdated commits, unexpected build hooks, and unauthorized automation activity. All compromised API keys and secrets should be rotated immediately, and affected npm packages should be unpublished with security advisories issued.
The attack underscores the growing threat of supply-chain compromises, where trusted developer tools become vectors for large-scale credential theft and malware propagation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
AUGUST 2025
750
JULY 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Exodus Intelligence ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in May 2026 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in April 2026 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in March 2026 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in February 2026 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in January 2026 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in December 2025 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in November 2025 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in October 2025 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in September 2025 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in August 2025 ??
What was Exodus Intelligence's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Exodus Intelligence's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Exodus Intelligence ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Exodus Intelligence's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?