An AI-generated crypto malware disguised as a routine package drained wallets in seconds, exploiting open-source ecosystems and sparking urgent concerns across the blockchain and developer communities.
Inside the Crypto Wallet Drainer: How One Script Moved Funds in Seconds
Crypto investors were put on alert after cybersecurity firm Safety revealed on July 31 that a malicious JavaScript package designed with artificial intelligence (AI) had been used to steal funds from crypto wallets. Disguised as a benign utility called @kodane/patch-manager on the Node Package Manager (NPM) registry, the package contained embedded scripts engineered to drain wallet balances. Paul McCarty, head of research at Safety, explained:
Safety’s malicious package detection technology has discovered an AI-generated malicious NPM package that functions as a sophisticated cryptocurrency wallet drainer, highlighting how threat actors are leveraging AI to create more convincing and dangerous malware.
news.bitcoin.com