Saturday, August 2, 2025
cryptonews100
No Result
View All Result
CryptoNews100
No Result
View All Result
Home Alt Coins Solana

AI-Generated Malicious npm Package Drains Solana Funds from 1,500+ Before Takedown

cryptonews100_tggfrn by cryptonews100_tggfrn
August 1, 2025
in Solana
0
AI-Generated Malicious npm Package Drains Solana Funds from 1,500+ Before Takedown
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
Sign up an get up to $1000 USDT!


Aug 01, 2025Ravie LakshmananMalware / Synthetic Intelligence

Cybersecurity researchers have flagged a malicious npm package deal that was generated utilizing synthetic intelligence (AI) and hid a cryptocurrency pockets drainer.

The package deal, @kodane/patch-manager, claims to supply “superior license validation and registry optimization utilities for high-performance Node.js purposes.” It was uploaded to npm by a person named “Kodane” on July 28, 2025. The package deal is not out there for obtain from the registry, however not earlier than it attracted over 1,500 downloads.

Software program provide chain safety firm Security, which discovered the library, mentioned the malicious options are marketed instantly within the supply code, calling it an “enhanced stealth pockets drainer.”

Particularly, the conduct is triggered as a part of a postinstall script that drops its payload inside hidden directories throughout Home windows, Linux, and macOS techniques, after which proceeds to hook up with a command-and-control (C2) server at “sweeper-monitor-production.up.railway[.]app.”

“The script generates a novel machine ID code for the compromised host and shares that with the C2 server,” Paul McCarty, head of analysis at Security, mentioned, noting that the C2 server lists two compromised machines.

Within the npm ecosystem, postinstall scripts are sometimes missed assault vectors—they run robotically after a package deal is put in, which means customers might be compromised with out ever executing the package deal manually. This creates a harmful blind spot, particularly in CI/CD environments the place dependencies are up to date routinely with out direct human evaluation.

Cybersecurity

The malware is designed to scan the system for the presence of a pockets file, and if discovered, it proceeds to empty all funds from the pockets to a hard-coded pockets deal with on the Solana blockchain.

Whereas this isn’t the primary time cryptocurrency drainers have been identified in open-source repositories, what makes @kodane/patch-manager stand out are clues that counsel the usage of Anthropic’s Claude AI chatbot to generate it.

This contains the presence of emojis, in depth JavaScript console logging messages, well-written and descriptive feedback, the README.md markdown file written in a mode that is in keeping with Claude-generated markdown recordsdata, and Claude’s sample of calling code adjustments as “Enhanced.”

The invention of the npm package deal highlights “how menace actors are leveraging AI to create extra convincing and harmful malware,” McCarty mentioned.

The incident additionally underlines rising issues in software program provide chain safety, the place AI-generated packages could bypass standard defenses by showing clear and even useful. This raises the stakes for package deal maintainers and safety groups, who now want to watch not simply recognized malware, however more and more polished, AI-assisted threats that exploit trusted ecosystems like npm.



Source link

Related articles

Qubetics Soars 950% in Debut Hour Polygon Upgrades for 95% Faster Transactions Cosmos Steady at $4.30

DevvStream Allocates $10M to Bitcoin and Solana for Crypto-Driven Sustainability Strategy

August 2, 2025
This New Ethereum Token Is Outperforming Solana and Cardano Combined In 2025

This New Ethereum Token Is Outperforming Solana and Cardano Combined In 2025

August 2, 2025
Tags: AIgenerateddrainsfundsmaliciousnpmPackageSolanatakedown
Share76Tweet47
Drive and walk to earn crypto!

Related Posts

Qubetics Soars 950% in Debut Hour Polygon Upgrades for 95% Faster Transactions Cosmos Steady at $4.30

DevvStream Allocates $10M to Bitcoin and Solana for Crypto-Driven Sustainability Strategy

by cryptonews100_tggfrn
August 2, 2025
0

DevvStream Corp., a Nasdaq-listed carbon administration agency, has allotted $10 million to Bitcoin and Solana as a part of a...

This New Ethereum Token Is Outperforming Solana and Cardano Combined In 2025

This New Ethereum Token Is Outperforming Solana and Cardano Combined In 2025

by cryptonews100_tggfrn
August 2, 2025
0

Solana and Cardano stay solidly inside the high 10 crypto listing, however July’s buying and selling exercise has seen a...

Solana ETFs Closer Than Ever: Here’s everything we know

Solana ETFs Closer Than Ever: Here’s everything we know

by cryptonews100_tggfrn
August 1, 2025
0

TL;DR: Grayscale & VanEck filed amended S-1s for Solana ETFs: GSOL (2.5% payment, money mannequin) and VSOL (1.5% payment, staking...

Cryptocurrency News Live: Bitcoin, Ethereum, Solana, memecoin updates; check prices, m-cap, trading activity

Cryptocurrency News Live: Bitcoin, Ethereum, Solana, memecoin updates; check prices, m-cap, trading activity

by cryptonews100_tggfrn
August 1, 2025
0

Cryptocurrency market sees widespread losses immediately The cryptocurrency market skilled a downturn immediately, with a number of tokens exhibiting important...

Ethereum And Solana Lead Crypto Derivatives Activity As Traders Favor Fractional Contracts

Ethereum And Solana Lead Crypto Derivatives Activity As Traders Favor Fractional Contracts

by cryptonews100_tggfrn
August 1, 2025
0

Nano Ethereum contracts dominate buying and selling quantity, main in each trades and notional worth. Solana and Bitcoin derivatives present...

Load More

Crypto Fear & Greed Index

Latest Crypto Fear & Greed Index

Recent News

"Come Back to America"… The Trump Administration Encourages Cryptocurrency Firms to …

"Come Back to America"… The Trump Administration Encourages Cryptocurrency Firms to …

August 2, 2025

Ethereum Targets Quantum-Safe Security, Fast Transactions — TradingView News

August 2, 2025
What Bitcoin’s Velocity Says About Its Future

What Bitcoin’s Velocity Says About Its Future

August 2, 2025

Categories

  • Bitcoin
  • Cardano
  • Chainlink
  • Cryptocurrency
  • Dogecoin
  • Elon Musk
  • Ethereum
  • Exchanges
  • Litecoin
  • Pokadot
  • Polygon
  • Real World Assets
  • Shiba Inu
  • Solana
  • sui
  • World Liberty Financial
  • XRP

Download the official CryptoNews100 Android App! Click the button below:

Tags

ADA (166) Bitcoin (651) BlockDAG (117) BTC (182) bullish (115) Buy (208) Cardano (277) ChainLink (211) crypto (761) Cryptocurrency (275) Detail (107) DOGE (131) Dogecoin (265) ETF (158) ETH (193) Ethereum (393) flash (108) gains (95) hits (98) Inu (206) key (100) launches (116) Link (104) market (213) million (110) News (369) Polkadot (133) POLYGON (138) prediction (120) Presale (104) price (580) rally (146) RWA (136) SHIB (121) Shiba (213) SOL (124) Solana (338) Sui (224) Surge (121) Surges (111) token (112) top (173) TradingView (112) Trump (157) XRP (473)

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Alt Coins
    • Cardano
    • Dogecoin
    • Litecoin
    • Pokadot
    • Polygon
    • Shiba Inu
    • Solana
    • XRP
  • Crypto Related DEALS

© 2023 Crypto News100 All Rights Reserved.
By visiting this website, you understand that the content provided within is for educational and entertainment purposes only. Nothing on this site may be constituted as financial advice and this site is not directing you to make any investments in cryptocurrency or in anything else. Thank you for visiting and please proceed responsibly.
As an Amazon Associate I earn from qualifying purchases.