logo

Same name, different hack: PyPI package targets Solana developers

ID: fa839acb-164a-598b-b2bc-ea365fd4e8d1

STIX ID: report--fa839acb-164a-598b-b2bc-ea365fd4e8d1

Feed Name: ReversingLabs Blog

Threat Score
72/100

Date Published: 2025-05-13

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs discovered a malicious PyPI package, 'solana-token', that masqueraded as a Solana developer utility and contained code to scan the Python execution stack, read local source files, and exfiltrate code and developer secrets to a hard-coded IP address; the package was downloaded over 600 times before PyPI removed it. The report highlights this as part of an ongoing trend of supply-chain attacks targeting cryptocurrency projects, notes similarities to prior PyPI campaigns (e.g., BIPClip), and provides indicators of compromise and recommendations for developer teams to monitor third-party modules closely.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.