Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Exodus Intelligence

Exodus Intelligence Vendor Cyber Rating & Cyber Score

exodusintel.com

Our team of world-class reverse engineers discovers exploitable critical vulnerabilities in common commercial software and hardware BEFORE they can be manipulated by attackers. Our actionable threat intelligence packages delivered through the Exodus Intelligence Vault arm you with thorough analysis and mitigation instructions to protect your organization. Contact us for an overview of our capabilities and examples of how they have been utilized by our clients.


Exodus Intelligence A.I CyberSecurity Scoring

Exodus Intelligence
Company Information
Website:https://www.exodusintel.com
Employees number:45
Number of followers:3,524
NAICS:541514
Industry Type:Computer and Network Security
Homepage:exodusintel.com
Exodus Intelligence Risk Score (AI oriented)
Between 700 and 749
logo
Exodus IntelligenceComputer and Network Security
Updated:
04/06/2026
732/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Exodus Intelligence Global Score (TPRM)
xxxx
logo
Exodus IntelligenceComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Exodus Intelligence
Exodus IntelligenceModerate
Current Score
732Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750Before Incident
Cyber Attack
04 Jun 2026Exodus Intelligence
Exodus, npm and GitHub: IronWorm Supply Chain Attack Uses Malicious npm Packages to Steal Developer Secrets

IronWorm Malware Campaign Targets Developers via Poisoned npm Packages

732After Incident
CRITICAL-18
GITEXONPM1780604646
IronWorm Malware Campaign Targets Developers via Poisoned npm Packages A sophisticated malware campaign, dubbed IronWorm, has been discovered targeting software developers particularly those in crypto and web3 through malicious npm packages. The attack leverages compromised developer workflows to steal credentials, API keys, and cryptocurrency wallet recovery phrases, while spreading autonomously via trusted supply-chain channels. ### How the Attack Works IronWorm infiltrates systems by hiding a Rust-based infostealer inside seemingly legitimate npm packages. When a developer runs `npm install`, the malware executes automatically, requiring no user interaction. The threat actor republished multiple npm packages from a hijacked account, embedding a hidden Linux binary in each. Once active, IronWorm employs a kernel-level rootkit to evade detection, masking its processes and network activity from standard monitoring tools like `ps` and `top`. It communicates with its operator via the Tor network and uses obfuscation techniques, including a modified UPX packer and per-string decryption, to hinder reverse engineering. ### Credential Theft & Self-Replication The malware aggressively harvests sensitive data, scanning for 86 environment variables (covering cloud platforms, CI/CD systems, and AI service keys) and 20+ credential file paths, including wallet configurations. A dedicated module targets the Exodus desktop wallet, capturing passwords and recovery phrases upon unlock. Another module extracts Kubernetes service account tokens from pods. IronWorm’s most dangerous feature is its self-replicating mechanism. After stealing credentials, it uses them to push backdated malicious commits into victims’ GitHub repositories, disguising them as routine maintenance (e.g., "fix: resolve lint warnings"). These infected packages are then published to npm, creating a supply-chain loop that spreads the malware further. Researchers identified 57 backdated commits across nine GitHub organizations, some timestamped years in the past to avoid scrutiny. ### Scope & Indicators of Compromise The campaign has impacted dozens of npm packages, including: - `[email protected]` - `[email protected]` - `[email protected]` - `[email protected]` Malicious commits were attributed to a fake GitHub email (`[email protected]`), and the operator’s Ethereum wallet address (`0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6`) was hardcoded in the malware. The C2 endpoint (`/api/agent`) operates over Tor, and the malicious binary resides in a hidden path (`tools/setup`). ### Mitigation & Response Security firm JFrog recommends auditing repositories for backdated commits, unexpected build hooks, and unauthorized automation activity. All compromised API keys and secrets should be rotated immediately, and affected npm packages should be unpublished with security advisories issued. The attack underscores the growing threat of supply-chain compromises, where trusted developer tools become vectors for large-scale credential theft and malware propagation.
INCIDENT DETAILS -
TYPE
Supply-Chain Attack, Malware Campaign
MOTIVATION
Credential theft, Cryptocurrency wallet compromise, Data exfiltration, Supply-chain propagation
IMPACT
Data Compromised: Credentials, API keys, Cryptocurrency wallet recovery phrases, Kubernetes service account tokens, Environment variablesSystems Affected: Developer workstations, CI/CD pipelines, GitHub repositories, npm packagesOperational Impact: Unauthorized access to cloud platforms, AI services, and cryptocurrency wallets; Supply-chain compromiseBrand Reputation Impact: Potential reputational damage to affected organizations due to supply-chain compromiseIdentity Theft Risk: High (recovery phrases and credentials stolen)
DATA BREACH
Type Of Data Compromised: Credentials, API keys, Cryptocurrency wallet recovery phrases, Kubernetes tokens, Environment variablesSensitivity Of Data: High (Personally Identifiable Information, Financial Data, Authentication Tokens)Data Exfiltration: Yes (via Tor network)Data Encryption: No (data stolen in plaintext)Personally Identifiable Information: Recovery phrases, Wallet passwords, API keys
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Exodus Intelligence ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Exodus Intelligence's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Exodus Intelligence's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Exodus Intelligence ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Exodus Intelligence's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?