Discussions of the cyber risks posed by AI focus on things like Claude’s Mythos AI model and its jaw-dropping ability to uncover exploitable software flaws – some that have gone unnoticed for decades.

But the risks to the software ecosystem posed by large language model AI are even bigger and more complex. Take the latest threat report by ReversingLabs, which found a seemingly routine code commit to an open-source crypto trading agent —co-authored by the Claude AI coding assistant—that introduced a malicious code dependency capable of compromising crypto wallets and stealing funds from the wallet owners.

According to a research report published on Tuesday, that dependency—an npm package masquerading as a validation library—is part of a broad, North Korean state-linked campaign that has been refining a dangerous new tactic: targeting the AI systems that increasingly write code on behalf of human developers.

The malware family uncovered in this campaign has been dubbed PromptMink. Its evolution offers a glimpse into the next phase of supply chain attacks—one where large language models (LLMs) are both tool and target.

A Supply Chain Attack, Reimagined

At its core, the attack follows a familiar pattern. Threat actors publish malicious packages to open-source repositories like npm, using “typo squatting” to disguise them as useful and established libraries. Unsuspecting developers pull them into their projects, granting attackers a foothold.

But PromptMink adds a twist. Instead of relying solely on human error, the campaign appears engineered to exploit AI coding agents. The malicious package, @validate-sdk/v2, was introduced into a crypto trading bot project via a commit partially generated by Anthropic’s Claude model. Once included, it executed code designed to harvest secrets—API keys, wallet credentials, and other sensitive data—from the host environment.

The implications are stark: AI systems trained to accelerate development can just as easily accelerate compromise.

Two Layers of Deception

What makes the campaign particularly resilient is its architecture. ReversingLabs researchers describe a two-layer strategy.

The first layer consists of benign-looking “bait” packages—libraries that appear functional and relevant to developers, especially in the Web3 ecosystem. These packages contain little or no malicious code themselves. Instead, they quietly import second-layer dependencies where the real payload resides.

This separation allows attackers to swap out malicious components as they are detected, without losing the credibility and download history of the top-level packages. It’s a modular, almost microservices-style approach to malware distribution—agile, disposable, and difficult to stamp out.

The tactic isn’t new. What’s new is how effectively it appears to fool AI systems. The report notes that these packages were likely “vibe-coded”—generated with the help of LLMs—and even contain stray prompts and comments left behind by those tools.

The Evolution of PromptMink

Over several months, PromptMink evolved rapidly—mirroring the iterative development cycles it exploits.

Early versions were simple JavaScript infostealers, scanning directories for .env and .json files and exfiltrating their contents. But as defenders caught on, the attackers adapted.

They shifted to obfuscation techniques aided by AI, embedding payloads in base64-encoded strings and hiding exfiltration endpoints. When that proved insufficient, they escalated.

By early 2026, the malware was bundled into massive standalone executables using Node.js’s Single Executable Application (SEA) format—a move clearly designed to evade detection. These binaries ballooned in size, sometimes exceeding 80MB, an anomaly in typical npm packages but effective at masking malicious logic.

The payloads also grew more invasive. Later versions added attackers’ SSH keys to infected systems, granting persistent remote access. Eventually, the campaign pivoted again—this time to compiled Rust modules, reducing file size while maintaining stealth and performance.

At its most advanced stage, PromptMink wasn’t just stealing credentials. It was exfiltrating entire codebases—intellectual property included.

In a statement to Security Ledger, Pezo, the ReversingLabs researcher who discovered the campaign, said the ability of AI to generate the same malicious functionality across a variety of coding languages – JS, Python and Rust – was impressive.

AI: Both a Weapon and a Weakness

The most unsettling aspect of the PromptMink campaign isn’t its technical sophistication. It’s the role of AI throughout the attack lifecycle.

LLMs appear to have been used to generate both the legitimate, first layer “bait” packages and the malicious layer 2 payloads. At the same time, those same kinds of models—embedded in developer workflows—were instrumental in propagating the attack.

“AI use… appears to have become an end-to-end process in the sense that malware authors are using it to generate malware…and AI is also adding it to projects,” Pezo said.

The PromptMink campaign highlights the need for more controls around AI coding agents, he said. “AI agents need more hard facts to work with, otherwise they will hallucinate them – and when they do, it is a flip of a coin whether what they come up with will be exploited by malicious actors, especially since they can test their lures on the same models at their discretion, before deploying them.”

This dual use reflects a broader shift in the threat landscape. As outlined in ReversingLabs’ broader research on software supply chains, attackers are increasingly targeting the weakest links in modern development pipelines, including automated tools and third-party dependencies.

AI coding assistants, trained on vast corpora of public code, are particularly susceptible. They lack the contextual awareness to distinguish between legitimate and malicious packages—especially when those packages are designed to look credible.

A Glimpse of What’s Next

The PromptMink campaign is proof of how attackers can weaponize tools like AI coding agents that are meant to improve software development. By exploiting the lack of security features in modern coding agents like Claude, malicious actors can quickly turn AI into an unwitting accomplice in supply chain compromises.

It also highlights a growing cybersecurity asymmetry: defenders are still adapting to traditional supply chain risks, while attackers are already iterating on AI-driven tactics.

The lesson for developers and organizations is clear. Trust in open-source ecosystems—and in the AI tools that navigate them—can no longer be implicit. Code suggestions, dependencies, and automated commits must be treated as untrusted input, subject to the same scrutiny as any external contribution. Because in the age of AI-assisted development, the question isn’t just whether your code is secure.

It’s whether your code was written by something that knows the difference.