BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

US State Actor Suspected in Targeting Russian Solana Devs With Malware

State-Sponsored “Solana-scan” Malware Targets Russian Crypto Developers with AI-Generated Code

  • Malware known as “Solana-scan” has targeted Russian Solana developers, focusing on crypto credentials and tokens.
  • The attack deploys malicious JavaScript packages on NPM under the username “cryptohan.”
  • Researchers suggest U.S. state-sponsored actors may be responsible, given evidence linking command servers to U.S. IP addresses.
  • Victims are Russian users and may include individuals connected to Ransomware activity.
  • The malware’s code appears to have been partially created using generative AI tools.

Russian developers within the Solana Blockchain community have been targeted by a type of malware called “Solana-scan,” according to research from software supply chain security firm Safety. This infostealer malware gathers sensitive information related to cryptocurrency holdings and may be connected to efforts by U.S. state-sponsored actors.

- Advertisement -

Two packages, “solana-pump-test” and “solana-spl-sdk,” were released through the JavaScript registry NPM by someone using the handle “cryptohan.” These packages claim to scan for Solana SDK components but instead capture users’ crypto credentials and token ownership data. Safety’s Head of Research, Paul McCarty, highlighted that the stolen data is sent to command and control servers with U.S.-based IP addresses.

“Cryptohan” is a widely used nickname in the crypto space, likely chosen to make the packages appear legitimate, McCarty stated. He also emphasized that the malware’s victims are specifically users with Russian IP addresses. This detail, combined with the destination of stolen data, led McCarty to suggest the involvement of a “state-sponsored actor.”

According to coverage in The Register, these attacks may be aimed at individuals connected to Russian ransomware gangs. Such groups have previously targeted U.S. infrastructure and demanded cryptocurrency payments, as noted in statements from U.S. government sources, including a press release from the Department of the Treasury.

A unique aspect of the “Solana-scan” malware, according to McCarty, is that parts of its coding show signs of being developed with generative Artificial Intelligence tools. He explained that the JavaScript payload fits patterns associated with large language models such as Claude.

- Advertisement -

The research suggests an advanced malware campaign using both technical deception (fake package names) and modern coding techniques to reach its targets. The overall aim appears to be the theft of crypto credentials, with evidence pointing to an ongoing digital conflict between U.S. and Russian actors involving the broader blockchain and cryptocurrency sectors.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

XRP ETFs Record High Inflows Amid Calls for $10 Rally

XRP is trading at $1.42, down 6% from its recent high of $1.50.Spot XRP...

RubyGems Halts Sign-Ups After Malicious Attack

RubyGems, a crucial package manager for Ruby software, has paused new user registrations due...

Kraken, Franklin Templeton partner on tokenized assets.

Payward (Kraken's parent) and Franklin Templeton are collaborating to bring traditional financial products onto...

Saylor: Key Act Language Critical For Digital Yield Markets

Strategy's Michael Saylor calls the CLARITY Act a catalyst for the next wave of...

Banks In “Panic Mode” Over Crypto Bill As Bitcoin Rises

The Bitcoin Price has surged past $82,000 as traders anticipate a massive $16 trillion...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading