solana-web3-patched@1.0.0
Malicious code in solana-web3-patched (npm)
Analysis
solana-web3-patched@1.0.0 is a combosquat of @solana/web3.js. Publisher email [account] impersonates "Solana Labs Maintainers". Both index.cjs.js and index.esm.js contain an inline credential harvester: (1) reads Solana wallet id.json, SSH keys, AWS credentials, .env files; (2) harvests process.env vars matching KEY/SECRET/MNEMONIC/TOKEN/SOLANA/etc; (3) rewrites ~/.config/solana/cli/config.yml to redirect RPC to attacker IP 104[.]239[.]66[.]223:8899; (4) exfiltrates via Telegram bot token [redacted-credential] to chat 8346336575; (5) anti-analysis guards (global.___SF___ dedup, IP self-check, hostname skips VPS/CI). Full Solana wallet + credential theft payload — recommend writeup.
- analyzed by
- Leitwacht
- first seen
- Jun 7, 2026, 11:03 PM
- analyzed
- Jun 8, 2026, 06:00 AM
Related advisories
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
- solana-web3-fork@1.0.0
- solana-web3-v1@1.0.0
- solana-web3-lts@1.0.0
- solana-web3-community@1.0.1
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.