Solana Library Supply Chain Attack Exposes Cryptocurrency Wallets
ID: 9e2da59c-a9b3-55dd-9942-400c3e277d50
STIX ID: report--9e2da59c-a9b3-55dd-9942-400c3e277d50
Feed Name: Infosecurity Magazine (News)
Threat Score
A supply-chain compromise of the @solana/web3.js npm library (versions 1.95.6 and 1.95.7), briefly published on 2 December 2024, contained an "addToQueue" backdoor that exfiltrated private keys to sol-rpc.xyz; attackers stole an estimated $130,000–$160,000 in SOL. Developers are advised to audit dependencies, update to 1.95.8, and rotate keys and program authorities if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
