AI crafted npm package drains Solana wallets from over 1500 users
A malicious npm package named @kodane/patch manager, created with the help of AI, was uploaded on July 28, 2025, posing as a legitimate tool for license validation and registry optimization. It contained a hidden postinstall script that deployed a cryptocurrency wallet drainer across Windows, macOS and Linux. The malware connected to a command and control server, identified victims, and drained Solana funds to a hard coded wallet. The package, which featured polished code with comments, emojis and styled documentation, was downloaded over 1500 times before removal.
https://thehackernews.com/2025/08/ai-generated-malicious-npm-package.html
Comments
Post a Comment