LWA-2026-2921 MAL-2026-10904 ↗ confirmed malware

solana-web3-v1@1.0.0

Malicious code in solana-web3-v1 (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1497 · Virtualization/Sandbox EvasionT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1005 · Data from Local SystemT1053.003 · CronT1102 · Web ServiceT1071 · Application Layer ProtocolT1567 · Exfiltration Over Web ServiceT1657 · Financial Theft

Analysis

solana-web3-v1@1.0.0 is a combosquat of @solana/web3.js (genuine Solana SDK). The package bundles a full credential-stealer/RAT inside the Node.js entry points (lib/index.cjs.js lines 11310-11351, lib/index.esm.js lines 11205-11246). Payload: (1) reads Solana wallet keypans, SSH keys, AWS credentials, .env files, and env vars matching KEY/SECRET/TOKEN/MNEMONIC/PASSWORD/RPC/NPM/GITHUB/SOLANA/INFURA etc.; (2) modifies ~/.config/solana/cli/config.yml to redirect RPC to hxxp://104[.]239[.]66[.]223:8899 to intercept all Solana transactions; (3) exfiltrates via Telegram bot [redacted-credential] to chat 8346336575; (4) installs crontab persistence on Unix; (5) runs a polling Telegram C2 loop supporting /keys, /ssh, /env, /wallet, /sh (remote shell), /die commands. The publisher is solana-foundations with throwaway email [account] — impersonating Solana Labs. Tarball scan status was "scanned" confirming the tarball-stage detectors ran; this is a clear true positive supply-chain attack.

analyzed by
Leitwacht
first seen
Jun 7, 2026, 11:03 PM
analyzed
Jun 8, 2026, 05:56 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.