Find notable cyber news and cases, enriched with sources, timelines, and signals.

Famous Chollima PromptMink supply-chain campaign targeting Web3 developers

Campaign
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

The PromptMink campaign is widening Famous Chollima's supply-chain intrusion playbook by pushing tainted npm packages into developer environments and stealing secrets. The operation targets Web3 developers and can expose crypto wallets, funds, source code, and other intellectual property. Its layered dependency chain and AI-generated code make the malicious packages harder to detect and easier to swap when removed. The same activity has also spread into related PyPI and GitHub-hosted delivery paths.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

Injective Labs SDK project GitHub repository hit by network compromise

Incident
H score21 First: 09.07.2026 23:10 Last: 09.07.2026 23:10 Sources 1

About this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Timeline

  1. 29.04.2026 17:43 2 articles · 2mo ago

    Famous Chollima PromptMink supply-chain campaign targeting Web3 developers

    Initial Disclosure

    The earliest PromptMink layer surfaced as a benign-looking npm SDK uploaded in October 2025 that concealed secret-stealing behavior behind a dependency chain. That initial phase focused on compromising developer systems and harvesting credentials before later variants added broader exfiltration and backdoor capability.

    Show sources