logo

Claude adds malware to crypto agent

ID: 16758d8f-70b7-5b8c-9fdd-2eee094503ee

STIX ID: report--16758d8f-70b7-5b8c-9fdd-2eee094503ee

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-30

Author: Vladimir Pezo

...
...

**Executive summary:** ReversingLabs uncovered PromptMink, a multi‑stage supply‑chain campaign attributed to North Korean group Famous Chollima that uses LLM‑crafted bait packages and malicious payload packages (notably @validate-sdk/v2 and related npm/PyPI packages) to steal .env/.json secrets, exfiltrate source code, and deploy SSH backdoors across Windows, macOS and Linux; the report includes technical analysis, IOCs (domains, IPs, C2 endpoints), and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.