Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Gaming
  • Legal
    • Legal and Regulatory
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
What's Hot

CLARITY Act- a Game-Changer Or Just Hype for Tokens?

April 29, 2026

TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

April 29, 2026

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

April 29, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Will BTC Drop After Powell’s Speech?

    April 29, 2026

    Institutional Investors Pour $1,200,000,000 Into Bitcoin and Crypto Assets in One Week: CoinShares

    April 29, 2026

    Canada proposes ban on BTC ATMs as fraud cases mount

    April 29, 2026

    Bitcoin Will Reshape Traditional Finance, Leaders Say

    April 29, 2026

    Bitmine’s Ethereum Accumulation Signals A New Corporate Playbook

    April 29, 2026

    Here’s Where It Will Start And End

    April 29, 2026

    Why Are Bitcoin & Ethereum Prices Dropping? What’s Behind Today’s Crypto Market Correction?

    April 28, 2026

    Ethereum Repeats 2021 Price Levels

    April 28, 2026

    XRP Price At $25,000? The ‘Divine’ Prediction That Is Setting The Community On Fire

    April 29, 2026

    XRP Price Trades Below $1.40, Can It Stabilize And Rebound?

    April 29, 2026

    Expert Says—Only One Condition Must Be Met

    April 29, 2026

    Binance Ethereum Supply Hits 2020 Levels While Staking Locks A Third: Repricing Ahead?

    April 28, 2026

    Meme Coin Market Faces Imbalance as Supply Rises, Demand Falls

    April 4, 2026

    Crypto Interest Rising Toward Meme Coin Sector

    January 9, 2026

    Memes Market Cap Adds $10B in Days: Fresh Capital or Dead-Cat-Bounce?

    January 5, 2026

    Meme Coin Market Surges Past $45B as Shiba Inu, PEPE, BONK Stage 54% Price Pump

    January 4, 2026

    CLARITY Act- a Game-Changer Or Just Hype for Tokens?

    April 29, 2026

    TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

    April 29, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    Will BTC Drop After Powell’s Speech?

    April 29, 2026
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

    April 29, 2026

    Rayls Joins LayerZero to Bolster Interoperability

    April 29, 2026

    Ethereum L2s Overtake Mainnet as Value Capture Debate Deepens

    April 29, 2026

    Anodos CEO Makes the Case for XRP Ledger as a Consumer Finance Layer

    April 29, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

    April 28, 2026

    US Sanctions Target Cambodian Scam Network Leaders

    April 27, 2026

    AI scams in crypto approach breaking point – OpenAI’s new image model shows why they could get worse

    April 27, 2026

    CLARITY Act- a Game-Changer Or Just Hype for Tokens?

    April 29, 2026

    TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

    April 29, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    Will BTC Drop After Powell’s Speech?

    April 29, 2026
  • Web 3
    1. Gaming
    2. View All

    B.AI and CROSS Transform the Future of AI in Web3 Gaming

    April 28, 2026

    How to Tokenize Assets: A Complete Guide for Beginners and Businesses

    April 27, 2026

    Tomoland Partners With Anome Protocol To Advance Web3 Gaming Engagement With DeFi Applications

    April 25, 2026

    KuCoin Launches KuCard in Australia, Expanding Real-World Crypto Payments

    April 24, 2026

    CLARITY Act- a Game-Changer Or Just Hype for Tokens?

    April 29, 2026

    TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

    April 29, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    Will BTC Drop After Powell’s Speech?

    April 29, 2026
  • Legal
    1. Legal and Regulatory
    2. Adoption
    3. View All

    CLARITY Act- a Game-Changer Or Just Hype for Tokens?

    April 29, 2026

    Crypto lobby backs formal removal of ‘reputation risk’ from bank examinations

    April 29, 2026

    CLARITY’s delay to test Wall Street’s $6.6 trillion stablecoin warning which is at odds with White House view

    April 29, 2026

    House Republicans Warn That the America’s Bitcoin Weakness Will Benefit China

    April 29, 2026

    What would Satoshi say? Director of the FBI appears at Bitcoin 2026

    April 29, 2026

    The South Korean bank powering Upbit is testing Ripple integration for cross-border payments

    April 28, 2026

    Hong Kong targets 10,000 BTC in purchases for Asia’s first regulated Bitcoin capital pool

    April 26, 2026

    DeFi losses are now 8,500% higher than TradFi breaches per dollar moved

    April 25, 2026

    CLARITY Act- a Game-Changer Or Just Hype for Tokens?

    April 29, 2026

    TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

    April 29, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    Will BTC Drop After Powell’s Speech?

    April 29, 2026
  • Analysis

    Dogecoin (DOGE) Price Breaks Above $0.10 as Open Interest Rises—Can Bulls Sustain the Move?

    April 29, 2026

    One Tech Giant’s Stock Could Double in Price in the Coming Years, Says Wedbush’s Dan Ives

    April 29, 2026

    Three XRP Scenarios Mapped From $2 to $100 as Real World Adoption Hits Three Continents

    April 29, 2026

    UB Price Breakout Gains Steam After OKX Listing Sparks Volatility

    April 28, 2026

    Fundstrat’s Tom Lee Outlines Roadmap for S&P 500 To Reach 7,700 This Year

    April 28, 2026
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What’s on the Ethereum Roadmap: Glamsterdam, Hegota and Beyond

    March 30, 2026

    What Is Bluesky? The Decentralized Social Media Rival to Elon Musk’s X

    March 27, 2026

    What Is Strategy (MSTR)? The Bitcoin Treasury Company

    February 21, 2026

    What Are Prediction Markets? How Polymarket, Kalshi and Myriad Work

    February 13, 2026

    CLARITY Act stablecoin fight shifts from yield to who captures digital-dollar economics

    April 29, 2026

    Over 80% of Bitcoin ETF assets hit Coinbase custody choke point with $74B at risk

    April 13, 2026

    FTX begins $2.2B payout. Can Bitcoin absorb another liquidity test?

    March 31, 2026

    BlinkEx investment platform infrastructure – matching, risk controls, reliability

    March 21, 2026

    CLARITY Act- a Game-Changer Or Just Hype for Tokens?

    April 29, 2026

    TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

    April 29, 2026

    Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

    April 29, 2026

    Will BTC Drop After Powell’s Speech?

    April 29, 2026
  • Tools
    • Market Overview
    • Exchange Tool
  • INFO@FREE.CC
Free.cc (Free Cryptocurrency)Free.cc (Free Cryptocurrency)
Home»Security and Privacy»Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W
Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W
Security and Privacy

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

April 29, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A malicious npm dependency linked to an AI-assisted code commit has been found stealing sensitive data and exposing crypto wallets.

According to researchers at ReversingLabs, the package, disguised as a validation tool, enabled attackers to exfiltrate secrets from infected environments and access funds.

The activity, tracked as PromptMink, involved the package @validate-sdk/v2, which was added to an autonomous trading agent in February 2026. The commit was reportedly co-authored by Anthropic’s Claude Opus model.

Layered Attack Structure Evades Detection

Attribution points to North Korean state-sponsored actor Famous Chollima (also known as APT37 or Reaper), which has been active since 2018 and is known for targeting cryptocurrency developers. The group relied on a two-layer package strategy that separates legitimate-looking tools from hidden malicious payloads.

Packages presented as useful Web3 utilities were used to attract adoption, while secondary dependencies quietly delivered the malware. This approach allowed attackers to maintain trust in widely visible components even as malicious elements were repeatedly replaced behind the scenes.

Across a seven-month period, the researchers tracked more than 60 packages and over 300 versions tied to the campaign, indicating sustained activity and refinement of delivery techniques.

Read more on software supply chain attacks: Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation

Malware Evolves Across Platforms

As the PromptMink campaign progressed, the underlying payload expanded well beyond simple credential theft. Early versions focused on harvesting sensitive files, but later iterations introduced broader capabilities that increased both impact and persistence.

These included:

  • Scanning directories for environment files and crypto-related data

  • Collecting system information such as usernames and IP addresses

  • Compressing entire project folders before exfiltration

  • Installing SSH keys to enable persistent remote access

See also  International Taskforce Dismantles €460m Crypto Fraud Network

The malware also evolved technically, moving from JavaScript-based code to compiled binaries and Rust-based payloads. This shift improved evasion and allowed the same core functionality to operate across Linux and Windows environments.

Evidence found in the code, including leftover prompts, suggests large language models (LLMs) were used in development. ReversingLabs noted that attackers are increasingly shaping malicious packages to appeal to AI coding assistants, extending supply chain risk into automated development workflows.

assisted Commit Crypto Dependency Linked Malicious npm Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto lobby backs formal removal of ‘reputation risk’ from bank examinations

April 29, 2026

Institutional Investors Pour $1,200,000,000 Into Bitcoin and Crypto Assets in One Week: CoinShares

April 29, 2026

Lawmakers Warn Crypto Clarity Will Decide U.S. Leadership as 2026 Election Looms

April 29, 2026

SEC, CFTC Chiefs Signal ‘New Day’ for U.S. Onshore Crypto, Tokenization and Future‑Proof Rules

April 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

XRP Price on the Cusp of Breakout as Bulls Target $10

September 21, 2025

Bankrupt Bitcoin Biz Founder Leaves $13m Hole

November 3, 2025

Stay ahead with the latest crypto news, market updates, blockchain insights, and trends. Your trusted source for everything happening in the digital asset world.


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

CLARITY Act- a Game-Changer Or Just Hype for Tokens?

April 29, 2026

TopNod and Pharos Roll Out AI-Driven Reward Mechanism with KiwiNod AI Agent

April 29, 2026

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

April 29, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Free.cc directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2026 free.cc - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.