logo

Solana blockchain's popular web3.js npm package backdoored to steal keys, funds

ID: 3a6b0fa3-19e5-554f-a79e-c6371f58ac1a

STIX ID: report--3a6b0fa3-19e5-554f-a79e-c6371f58ac1a

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-12-05

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

**Executive summary:** A compromised @solana npm account published malicious versions (1.95.6 and 1.95.7) of the widely used @solana/web3.js library on Dec 3, 2024; the backdoor exfiltrated private keys (reported via Cloudflare headers), allowing attackers to drain funds from affected dapps, CVE-2024-54134 (CVSS 8.3) was assigned, the malicious versions were available for a short window and subsequently unpublished, and reported losses are approximately USD 130K.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.