solana-web3-stable@1.0.0
Malicious code in solana-web3-stable (npm)
Analysis
CRITICAL: solana-web3-stable@1.0.0 is a combosquat of @solana/web3.js. The bundled Node.js builds (index.cjs.js, index.esm.js) contain an injected payload (~lines 11210-11260) that: (1) Evades analysis by checking if the victim IP matches the attacker's own IP 104[.]239[.]66[.]223 and exits on server/VM-like hostnames; (2) Harvests Solana wallet keys (~/.config/solana/id.json, ~/.solana/id.json), SSH keys (~/.ssh/id_rsa, ~/.ssh/id_ed25519), AWS credentials (~/.aws/credentials), and .env files; (3) Scans all process.env variables for sensitive keywords (KEY, SECRET, MNEMONIC, PRIVATE, TOKEN, PASSWORD, AWS, NPM, GITHUB, SOLANA, ETHERSCAN, ALCHEMY, INFURA); (4) Rewrites ~/.config/solana/cli/config.yml to redirect json_rpc_url to hxxp://104[.]239[.]66[.]223:8899 (RPC hijacking for wallet draining); (5) Exfiltrates stolen data via Telegram bot (token [redacted-credential], chat 8346336575) with HMAC-based victim fingerprinting. Package has no lifecycle hooks (fires on require/import), uses disposable email [account], impersonates solana-foundations (with trailing 's'), and contains 1.1MB of sourcemap files. This is a full-spectrum credential harvester + Solana wallet drainer targeting the Solana developer ecosystem.
- analyzed by
- Leitwacht
- first seen
- Jun 7, 2026, 11:03 PM
- analyzed
- Jun 8, 2026, 06:04 AM
Related advisories
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
- solana-web3-v1@1.0.0
- solana-web3-lts@1.0.0
- solana-web3-community@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.