logo

Solana web3.js Supply Chain Attack (Campaign)

ID: ce756fa1-7efe-5956-a60f-11cbe00eeeb3

STIX ID: report--ce756fa1-7efe-5956-a60f-11cbe00eeeb3

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-12-04

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

On December 2–3, 2024 a supply-chain compromise of the @solana/web3.js JavaScript library (versions 1.95.6 and 1.95.7) introduced an obfuscated backdoor that captured and exfiltrated private keys to an attacker-controlled domain (sol-rpc.xyz), resulting in over $190,000 stolen; the malicious code was deployed via a compromised npm account, active for approximately five hours, and mitigated by revoking the malicious packages, taking down the C2, and releasing a patched version (1.95.8).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.