Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent
ID: c3152597-bf28-540a-b54e-531d36c81700
STIX ID: report--c3152597-bf28-540a-b54e-531d36c81700
Feed Name: cybersecurityNews.com
PromptMink is a multi-month malicious npm supply-chain campaign that inserted a benign-looking dependency which pulled in a hidden malicious package (@validate-sdk/v2). The payload scans for environment and config files to exfiltrate credentials (targeting crypto wallets), can plant an SSH key on Linux for persistent access, and later Rust variants steal full project source; ReversingLabs attributes the activity to Famous Chollima and notes the attack used a two-layer packaging strategy and even a commit co-authored by Claude Opus to increase the chance of inclusion in developer projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
