2 Sources
[1]
Emoji use suggests crypto-stealing NPM package was AI-made
Kodane code was either machine-generated or done by a teenager An NPM package packed with cryptocurrency-stealing malware appears to have been largely AI-generated, as evidenced by its liberal use of emojis and other telltale signs. Security shop Safety found the Kodane attack code in an npm
[2]
AI-Generated Malicious npm Package Drains Solana Funds from 1,500+ Before Takedown
Cybersecurity researchers have flagged a malicious npm package that was generated using artificial intelligence (AI) and concealed a cryptocurrency wallet drainer. The package, @kodane/patch-manager, claims to offer "advanced license validation and registry optimization utilities for
Share
Copy Link
A malicious npm package, likely created using AI, has been discovered stealing cryptocurrency from users' wallets. The package, masquerading as a legitimate tool, highlights the growing threat of AI-assisted malware in software supply chains.
In a concerning development at the intersection of artificial intelligence and cybersecurity, researchers have uncovered a malicious npm package that appears to have been generated using AI. The package, named "@kodane/patch-manager," was designed to drain cryptocurrency wallets and managed to attract over 1,500 downloads before being taken down
1
.
Source: Hacker News
The malicious package masqueraded as a legitimate tool, claiming to offer "license validation and registry optimization" for Node.js applications. However, upon closer inspection, security researchers from Safety discovered its true nature as an "Enhanced Stealth Wallet Drainer"
2
.The malware's functionality is particularly cunning. It targets cryptocurrency wallets on Windows, macOS, and Linux systems, draining funds to a predefined address on the Solana blockchain. Interestingly, it leaves enough currency in the wallet to cover transaction fees, potentially delaying detection
1
.What sets this malware apart is the strong indication that it was generated using AI, specifically Anthropic's Claude model. Paul McCarty, Safety's head of research, pointed out several telltale signs:
1
2

Source: The Register
McCarty noted, "For some reason code generating AI platforms love to put emojis in source code. No developer that I know does this, unless they are 14"
1
.The discovery of this AI-generated malware raises significant concerns about software supply chain security. The package's professional appearance and well-written documentation could easily deceive developers and bypass conventional security measures
2
.Of particular concern is the use of postinstall scripts, which run automatically after a package is installed. This creates a dangerous blind spot, especially in CI/CD environments where dependencies are updated routinely without direct human review
2
.Related Stories
The malicious package was uploaded on July 28, 2025, and flagged as malicious about two days later. In that short time, it managed to attract over 1,500 downloads. While all versions have now been removed, the actual impact remains unclear as the number of unique IP addresses that downloaded the package is unknown
1
2
.This incident highlights the growing threat of AI-assisted malware creation. As AI tools become more sophisticated and accessible, cybercriminals can potentially create more convincing and dangerous malware that can evade traditional detection methods
2
.The cybersecurity community now faces the challenge of not only monitoring for known malware but also developing strategies to detect and mitigate increasingly polished, AI-assisted threats that exploit trusted ecosystems like npm
2
.Summarized by
Navi
[1]
27 May 2026•Technology

01 Jun 2026•Technology

13 Apr 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology