LWA-2026-2916 MAL-2026-10900 ↗ confirmed malware

solana-web3-fork@1.0.0

Malicious code in solana-web3-fork (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1497 · Virtualization/Sandbox EvasionT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1053.003 · CronT1102 · Web ServiceT1071 · Application Layer ProtocolT1567 · Exfiltration Over Web ServiceT1657 · Financial Theft

Analysis

CRITICAL TP: solana-web3-fork@1.0.0 is a combosquat of the real @solana/web3.js package, published by solana-foundations (throwaway email [account]). The lib/index.cjs.js and lib/index.esm.js bundles contain appended top-level malware (~lines 11210-11330) that: (1) checks if host IP is 104[.]239[.]66[.]223 (attacker's own IP — anti-analysis); (2) skips VPS/host/server hostnames (more anti-analysis); (3) harvests Solana wallet keys (~/.config/solana/id.json), SSH private keys, AWS credentials, .env files; (4) scrapes env vars matching KEY/SECRET/MNEMONIC/PRIVATE/TOKEN/GITHUB/NPM/SOLANA/etc; (5) rewrites Solana CLI config to redirect RPC to hxxp://104[.]239[.]66[.]223:8899; (6) exfiltrates everything via Telegram Bot API (bot token [redacted-credential], chat ID 8346336575) with HMAC-authenticated requests. Runs on require()/import — no lifecycle hook needed.

analyzed by
Leitwacht
first seen
Jun 7, 2026, 11:03 PM
analyzed
Jun 8, 2026, 05:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.