Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets
ID: 06d35373-8fc3-53db-867d-a85e60eb3543
STIX ID: report--06d35373-8fc3-53db-867d-a85e60eb3543
Feed Name: Infosecurity Magazine (News)
Threat Score
A supply-chain campaign named PromptMink abused npm packages (notably package@validate-sdk/v2) to deliver infostealing malware that exfiltrated secrets and accessed cryptocurrency wallets; researchers attribute the activity to North Korean APT Famous Chollima and observed a layered delivery strategy, cross-platform evolution from JS to compiled/Rust payloads, and persistent backdoor capabilities over a multi-month, multi-package campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
