North Korea AI‑Powered npm Malware Hits Solana

SkimNews Take
The attackers' use of AI to generate code for a seemingly benign npm package highlights a new vector for supply chain attacks, where the sheer volume of AI-generated code could obscure malicious components.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- North Korea deploys the PromptMink malware campaign, leveraging a malicious npm package to exfiltrate crypto wallet secrets from Solana tools.
- Anthropic's Claude Opus LLM co‑authored the Feb 28 2026 commit that introduced the tainted @validate-sdk/v2 dependency.
- Famous Chollima (aka Shifty Corsair) orchestrates the multi‑layered npm attack, swapping out second‑layer malicious packages when detected.
Why it matters: Crypto developers lose funds as North Korea’s PromptMink steals credentials after a Feb 28 2026 commit, prompting heightened scrutiny of AI‑generated npm code and tighter supply‑chain defenses.




