LWA-2026-10828 confirmed malware
@solana-js/web3@1.91.3
Malicious code in @solana-js/web3 (npm)
T1195.002 · Compromise Software Supply ChainT1059.001 · PowerShellT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1055 · Process Injection
Analysis
The package impersonates the Solana web3.js SDK. Its postinstall hook (scripts/postinstall.js) runs only on Windows and launches a hidden, detached PowerShell process with a base64-encoded payload. The payload P/Invokes kernel32 VirtualAlloc/CreateThread/WaitForSingleObject, downloads a binary from hxxps://files[.]catbox[.]moe/a3loxy[.]bin, copies it into executable memory, and runs it in a new thread — an in-memory shellcode loader that executes a remote payload on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 10:41 AM
- analyzed
- Aug 8, 2026, 10:41 AM
Related advisories
- bigops-security@35.8.8
- delivery-ci-jira@35.5.2
- bigops-api-customer@35.8.9
- express-middle@5.5.1
- streak-grid-core@1.0.0
- type-unique@3.1.3
- type-astr@3.2.3
- type-atob@3.3.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.