logo

Claude-Generated Commit Adds PromptMink Malware to Crypto Trading Agent

ID: c3152597-bf28-540a-b54e-531d36c81700

STIX ID: report--c3152597-bf28-540a-b54e-531d36c81700

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Tushar Subhra Dutta

...
...

PromptMink is a multi-month malicious npm supply-chain campaign that inserted a benign-looking dependency which pulled in a hidden malicious package (@validate-sdk/v2). The payload scans for environment and config files to exfiltrate credentials (targeting crypto wallets), can plant an SSH key on Linux for persistent access, and later Rust variants steal full project source; ReversingLabs attributes the activity to Famous Chollima and notes the attack used a two-layer packaging strategy and even a commit co-authored by Claude Opus to increase the chance of inclusion in developer projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.