Malware found in Solana npm library raises the bar for crypto security
ID: 4d6a75ce-6226-5908-be23-ef9a3cb21008
STIX ID: report--4d6a75ce-6226-5908-be23-ef9a3cb21008
Feed Name: ReversingLabs Blog
Threat Score
Unknown attackers compromised the widely used @solana/web3.js npm package (v1.95.6 and v1.95.7), inserting a backdoor (including an "addToQueue" function) that exfiltrates private keys to https://sol-rpc.xyz; GitHub and researchers recommend downgrading to 1.95.5 or upgrading to 1.95.8 and rotating all secrets, and evidence suggests a maintainer publish-account compromise broadened the potential blast radius across thousands of dependent projects and many users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
