US State Actor Suspected in Targeting Russian Solana Devs With Malware

State-Sponsored “Solana-scan” Malware Targets Russian Crypto Developers with AI-Generated Code

  • Malware known as “Solana-scan” has targeted Russian Solana developers, focusing on crypto credentials and tokens.
  • The attack deploys malicious JavaScript packages on NPM under the username “cryptohan.”
  • Researchers suggest U.S. state-sponsored actors may be responsible, given evidence linking command servers to U.S. IP addresses.
  • Victims are Russian users and may include individuals connected to Ransomware activity.
  • The malware’s code appears to have been partially created using generative AI tools.

Russian developers within the Solana Blockchain community have been targeted by a type of malware called “Solana-scan,” according to research from software supply chain security firm Safety. This infostealer malware gathers sensitive information related to cryptocurrency holdings and may be connected to efforts by U.S. state-sponsored actors.

- Advertisement -

Two packages, “solana-pump-test” and “solana-spl-sdk,” were released through the JavaScript registry NPM by someone using the handle “cryptohan.” These packages claim to scan for Solana SDK components but instead capture users’ crypto credentials and token ownership data. Safety’s Head of Research, Paul McCarty, highlighted that the stolen data is sent to command and control servers with U.S.-based IP addresses.

“Cryptohan” is a widely used nickname in the crypto space, likely chosen to make the packages appear legitimate, McCarty stated. He also emphasized that the malware’s victims are specifically users with Russian IP addresses. This detail, combined with the destination of stolen data, led McCarty to suggest the involvement of a “state-sponsored actor.”

According to coverage in The Register, these attacks may be aimed at individuals connected to Russian ransomware gangs. Such groups have previously targeted U.S. infrastructure and demanded cryptocurrency payments, as noted in statements from U.S. government sources, including a press release from the Department of the Treasury.

A unique aspect of the “Solana-scan” malware, according to McCarty, is that parts of its coding show signs of being developed with generative Artificial Intelligence tools. He explained that the JavaScript payload fits patterns associated with large language models such as Claude.

- Advertisement -

The research suggests an advanced malware campaign using both technical deception (fake package names) and modern coding techniques to reach its targets. The overall aim appears to be the theft of crypto credentials, with evidence pointing to an ongoing digital conflict between U.S. and Russian actors involving the broader blockchain and cryptocurrency sectors.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

OpenClaw npm Package a Stealthy Data-Stealing Trojan

A malicious npm package posing as an OpenClaw AI installer has been deployed to...

Wall Street Warns of 35% Meltdown Risk Amid Iran War

Wall Street firms like JPMorgan are warning of a potential 10% S&P 500 correction...

Coinbase Launches Futures Trading in 26 European Countries

Coinbase launched regulated crypto futures trading across 26 European Union countries for the first...

US Secretly Buys Russian Microwave Weapons

US Homeland agents reportedly purchased and tested a secret, portable microwave weapon from Russian...

Ether Tops $2K as Derivatives Leverage Hits Record High

Ether surged past $2,000 on Monday as speculative trading intensified, with over 110,000 ETH...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...