By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library
Tech News

Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library

By Viral Trending Content 4 Min Read
Share
SHARE

Dec 04, 2024Ravie LakshmananSupply Chain Attack

Web3.js npm Library

Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3.js npm library that involved pushing two malicious versions capable of harvesting users’ private keys with an aim to drain their cryptocurrency wallets.

The attack has been detected in versions 1.95.6 and 1.95.7. Both these versions are no longer available for download from the npm registry. The package is widely used, attracting over 400,000 weekly downloads.

“These compromised versions contain injected malicious code that is designed to steal private keys from unsuspecting developers and users, potentially enabling attackers to drain cryptocurrency wallets,” Socket said in a report.

@solana/web3.js is an npm package that can be used to interact with the Solana JavaScript software development kit (SDK) for building Node.js and web apps.

Cybersecurity

According to Datadog security researcher Christophe Tafani-Dereeper, “the backdoor inserted in v1.95.7 adds an ‘addToQueue’ function which exfiltrates the private key through seemingly-legitimate CloudFlare headers” and that “calls to this function are then inserted in various places that (legitimately) access the private key.”

The command-and-control (C2) server to which the keys are exfiltrated to (“sol-rpc[.]xyz”) is currently down. It was registered on November 22, 2024, on domain registrar NameSilo.

It’s suspected that the maintainers of the npm package fell victim to a phishing attack that allowed the threat actors to seize control of the accounts and publish the rogue versions.

“A publish-access account was compromised for @solana/web3.js, a JavaScript library that is commonly used by Solana dApps,” Steven Luscher, one of the library maintainers, said in the release notes for version 1.95.8.

“This allowed an attacker to publish unauthorized and malicious packages that were modified, allowing them to steal private key material and drain funds from dApps, like bots, that handle private keys directly. This issue should not affect non-custodial wallets, as they generally do not expose private keys during transactions.”

Luscher also noted that the incident only impacts projects that directly handle private keys and that were updated within the window of 3:20 p.m. UTC and 8:25 p.m. UTC on December 2, 2024.

Users who are relying on @solana/web3.js as a dependency are advised to update to the latest version as soon as possible, and optionally rotate their authority keys if they suspect they are compromised.

The disclosure comes days after Socket warned of a bogus Solana-themed npm package named solana-systemprogram-utils that’s designed to sneakily reroute a user’s funds to an attacker-controlled hard-coded wallet address in 2% of transactions.

Cybersecurity

“The code cleverly masks its intent by functioning normally 98% of the time,” the Socket Research Team said. “This design minimizes suspicion while still allowing the attacker to siphon funds.”

It also follows the discovery of npm packages such as crypto-keccak, crypto-jsonwebtoken, and crypto-bignumber that masquerade as legitimate libraries but contain code to siphon credentials and cryptocurrency wallet data, once again highlighting how threat actors are continuing to abuse the trust developers place in the open-source ecosystem.

“The malware threatens individual developers by stealing their credentials and wallet data, which can lead to direct financial losses,” security researcher Kirill Boychenko noted. “For organizations, compromised systems create vulnerabilities that can spread throughout enterprise environments, enabling widespread exploitation.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Phomemo PM64D: The New Generation Touchscreen Shipping Label Printer Balancing Speed and Portability

OnePlus 15 vs Pixel 10 Pro Review: Which Phone is Better?

Enterprise Ireland leads Irish Tech Delegation Targets Nordic Growth and VC Funding at Slush 2025

Gemini 3 Is Here—and Google Says It Will Make Search Smarter

Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale

TAGGED: cryptocurrency, Cyber Security, Cybersecurity, Internet, JavaScript, NPM, Open Source, phishing, Solana, supply chain attack, threat detection, Wallet Security
Share This Article
Facebook Twitter Copy Link
Previous Article Trump Uses Unusual Tactic in Conducting Foreign Policy During Transition
Next Article AI training consent a ‘perfect use case’ for blockchain — Aptos co-founder
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Key Epstein files vote passes US House in overwhelming 427–1 majority
World News
Phomemo PM64D: The New Generation Touchscreen Shipping Label Printer Balancing Speed and Portability
Tech News
Internet Computer (ICP) breaks out of a falling wedge pattern, $7 within reach
Crypto
OnePlus 15 vs Pixel 10 Pro Review: Which Phone is Better?
Tech News
Interlull ‘On This Day’
Sports
Megabonk Dev Officially Withdraws It From The Game Awards
Gaming News
France and Germany support simplification push for digital rules as Commission preps AI Act review
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Key Epstein files vote passes US House in overwhelming 427–1 majority

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Key Epstein files vote passes US House in overwhelming 427–1 majority
November 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?