Solana blockchain's popular web3.js npm package backdoored to steal keys, funds
ID: 3a6b0fa3-19e5-554f-a79e-c6371f58ac1a
STIX ID: report--3a6b0fa3-19e5-554f-a79e-c6371f58ac1a
Feed Name: The Register (Security)
Threat Score
**Executive summary:** A compromised @solana npm account published malicious versions (1.95.6 and 1.95.7) of the widely used @solana/web3.js library on Dec 3, 2024; the backdoor exfiltrated private keys (reported via Cloudflare headers), allowing attackers to drain funds from affected dapps, CVE-2024-54134 (CVSS 8.3) was assigned, the malicious versions were available for a short window and subsequently unpublished, and reported losses are approximately USD 130K.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
