logo

Malicious npm and PyPI target Solana Private keys to steal funds from victims’ wallets

ID: 7fdff0ee-cb25-5ab0-b2b1-dc24e0f6bf87

STIX ID: report--7fdff0ee-cb25-5ab0-b2b1-dc24e0f6bf87

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2025-01-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers discovered malicious npm and PyPI packages (typosquatting popular Solana-related libraries) that exfiltrate Solana private keys via Gmail SMTP and automatically transfer up to 98% of wallet funds to an attacker-controlled Solana address; malicious GitHub repositories were also used to amplify the campaign and the report includes IoCs and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.