Tuesday, September 8, 2026

Hackers Leverage AI to Craft Malicious NPM Package That Drains Crypto Wallets

Security researchers at Safety have uncovered an AI-generated malicious NPM package dubbed @kodane/patch-manager, engineered as an advanced cryptocurrency wallet drainer.

This package, posing as a benign “NPM Registry Cache Manager” for license validation and registry optimization, embeds sophisticated mechanisms to siphon funds from developers’ and users’ crypto wallets.

Published under the NPM username “Kodane,” the malware’s source code brazenly self-identifies as the “ENHANCED STEALTH WALLET DRAINER” in its internal documentation, revealing its true intent despite elaborate disguises.

Crypto Wallets
@kodane/patch-manager

The package’s postinstall script, executed via Node.js, initiates the infection chain by renaming and making executable key files monitor.js, sweeper.js, and utils.js before installing them into hidden directories mimicking legitimate NPM cache paths.

On macOS, it targets ~/Library/Application Support/npm/registry-cache/; on Linux, ~/.local/share/npm/registry-cache/; and on Windows, %APPDATA%\npm\registry-cache/, where it further conceals the directory using the attrib +H command for hidden attributes.

Sophisticated Wallet Drainer

Once deployed, the malware achieves persistence by spawning a detached background process from connection-pool.js, which establishes communication with a command-and-control (C2) server at https://sweeper-monitor-production.up.railway.app.

This script generates a unique machine identifier for the compromised host and relays it to the C2, which remains publicly accessible without authentication, managing multiple infected systems.

Researchers observed active “funding events” on the server, with logs indicating recent compromises on hosts like SmFtZXNz and bG9jYWxo, though the operator periodically clears records.

Upon detecting wallet files, the process hands off to transaction-cache.js, which performs the actual draining identifying assets, calculating transfer fees, and sweeping the majority of funds while leaving just enough for transaction costs.

Crypto Wallets
compromised wallets

Utilizing a hardcoded Solana RPC endpoint at https://mainnet.helius-rpc.com/?api-key=97188cdf-0b78-4cba-86f9-c4bbbd44c6aa, it funnels stolen assets to the address B2XwbrGSXs3LAAcqFqKqGUug5TFA1Bug2NNGH3F3mWNK, which exhibits high transaction volume suggestive of widespread exploitation.

The malware’s creator, potentially from a UTC+5 timezone region such as Russia, China, or India based on publication timestamps, released 19 versions starting July 28, 2025.

The package amassed over 1,500 downloads before NPM flagged it as malicious on July 30, 2025, at 4:56 PM AEST, rendering it unavailable.

Analysis of timestamps and the name “Kodane” (Japanese for “child”) offers limited insights into the actor’s origin, but the code’s polish points to AI assistance.

Clues Pointing to AI-Generated Malware Code

Several hallmarks in the package’s structure betray its AI origins, likely from tools like Claude.

The source code features excessive emojis, atypical for professional developers, alongside verbose console.log statements that redundantly echo comments.

Comments are overly abundant and lucid, following a uniform pattern across files contrasting with the cryptic, team-specific notes in human-authored code.

The README.md employs consistent markdown styling with numerous inline code snippets, a signature of AI generation. Notably, the malware labels itself “Enhanced,” a common AI convention for modified outputs.

This AI leverage enables threat actors to produce convincing, professional-grade documentation and code, evading initial scrutiny while embedding stealthy persistence and exfiltration logic.

Such tactics underscore the growing risk of AI-amplified malware in supply chain attacks, where seemingly legitimate packages can compromise development environments and downstream users.

Indicators of Compromise (IOCs)

CategoryIOC Details
NPM Packages@kodane/patch-manager
Files (SHA-256)7a0a3e64ecb4212ce08315400ed7ed79617843e2bc4326439ca8b81d1960ecbc (monitor.js)
3aa51674e3d46062b6de2cfd6c20f8b70fef2b6a28add462a870f686e387f9de (sweeper.js)
e8e5ace2a791d519e69c547e1a8491bf6a5d3060c080ff7e8350b86f2a0aab30 (utils.js)
f64a8ac3604c712fc1ace85c3262da3dfe693a4b4082f7365f849eea6908ee8b (post-install.js)
Email Addresses[email protected]
Domains/URLshttps://sweeper-monitor-production.up.railway.app
https://sweeper-monitor.railway.app
http://va.vision-node.com:8899
https://sweeper-monitor-production.up.railway.app

Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Related Articles

Recent News