solana-web3-fork@1.0.0
Malicious code in solana-web3-fork (npm)
Analysis
CRITICAL TP: solana-web3-fork@1.0.0 is a combosquat of the real @solana/web3.js package, published by solana-foundations (throwaway email [account]). The lib/index.cjs.js and lib/index.esm.js bundles contain appended top-level malware (~lines 11210-11330) that: (1) checks if host IP is 104[.]239[.]66[.]223 (attacker's own IP — anti-analysis); (2) skips VPS/host/server hostnames (more anti-analysis); (3) harvests Solana wallet keys (~/.config/solana/id.json), SSH private keys, AWS credentials, .env files; (4) scrapes env vars matching KEY/SECRET/MNEMONIC/PRIVATE/TOKEN/GITHUB/NPM/SOLANA/etc; (5) rewrites Solana CLI config to redirect RPC to hxxp://104[.]239[.]66[.]223:8899; (6) exfiltrates everything via Telegram Bot API (bot token [redacted-credential], chat ID 8346336575) with HMAC-authenticated requests. Runs on require()/import — no lifecycle hook needed.
- analyzed by
- Leitwacht
- first seen
- Jun 7, 2026, 11:03 PM
- analyzed
- Jun 8, 2026, 05:56 AM
Related advisories
- solana-web3-v1@1.0.0
- solana-web3-lts@1.0.0
- solana-web3-community@1.0.1
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
- solana-web3-fixed@1.0.0
- solana-js-client@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.