LWA-2026-2918 MAL-2026-10899 ↗ confirmed malware

solana-web3-fixed@1.0.0

Malicious code in solana-web3-fixed (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1497 · Virtualization/Sandbox EvasionT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1053.003 · CronT1102 · Web ServiceT1071 · Application Layer ProtocolT1567 · Exfiltration Over Web ServiceT1657 · Financial Theft

Analysis

TRUE POSITIVE: solana-web3-fixed@1.0.0 is a combosquatting Solana wallet/credential stealer. The built bundles (lib/index.cjs.js L11316-11336, lib/index.esm.js L11211-11236) contain injected malware that: (1) checks for anti-analysis by testing if external IP == 104[.]239[.]66[.]223 (attacker's own IP) or hostname matches /vps|server|host|node|instance/ to evade sandboxes; (2) steals Solana wallet keys (~/.config/solana/id.json, ~/.solana/id.json), SSH private keys (~/.ssh/id_rsa, ~/.ssh/id_ed25519), AWS credentials, and all .env files; (3) scrapes process.env for tokens containing KEY, SECRET, MNEMONIC, PRIVATE, TOKEN, PASSWORD, SOLANA, NPM, GITHUB, AWS, etc.; (4) hijacks solana CLI config to redirect RPC traffic to attacker-controlled hxxp://104[.]239[.]66[.]223:8899; (5) exfiltrates via Telegram bot (token: [redacted-credential], chat ID: 8346336575) using api[.]telegram[.]org/bot.../sendMessage. Publisher is "solana-foundations" (combosquatting Solana Foundation) with disposable email [account] — impersonating Solana Labs. No lifecycle hooks needed; the payload runs as a top-level side-effect on require().

analyzed by
Leitwacht
first seen
Jun 7, 2026, 11:03 PM
analyzed
Jun 8, 2026, 05:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.