logo

Malicious Solana Packages Attacking Devs Abusing Slack And ImgBB For Data Theft

ID: 996d40ef-4b4e-55ba-b456-85119440ec30

STIX ID: report--996d40ef-4b4e-55ba-b456-85119440ec30

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-01-09

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Malicious npm packages targeting Solana developers deploy a Windows trojan and PowerShell-based keylogger and screenshot stealer that exfiltrate captured keystrokes and images via Slack webhooks, ImgBB uploads, and Discord; the packages (solanacore, solana-login, walletcore-gen) share identical code, were downloaded ~1,900 times, and explicitly reference LOCKBITAI while lacking obfuscation, indicating active distribution and potential credential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.