logo

Malicious AI-generated npm package hits Solana users

ID: a4067ac5-ef32-5d8f-a4d4-ee378291c387

STIX ID: report--a4067ac5-ef32-5d8f-a4d4-ee378291c387

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2025-08-01

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A malicious, likely AI-generated npm package named @kodane/patch-manager was published and downloaded over 1,500 times before removal; it used postinstall scripts and hidden cache folders to persist across macOS, Linux, and Windows, connected to an open C2 that logged wallet finds, and executed a transaction script to drain Solana wallets to a hardcoded address — researchers published indicators of compromise and analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.