solana-address-codec@1.0.2
Malicious code in solana-address-codec (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
solana-address-codec is a 96-byte re-export wrapper that depends on base58-core, a known malicious package. The package's index.js simply re-exports functions from base58-core, making it a dependency-chain attack — installing solana-address-codec pulls in the malicious base58-core dependency. The package has no repository, no lifecycle hooks, and its sole purpose is to act as a trojanized dependency vector.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 11:11 PM
- analyzed
- Jul 2, 2026, 10:57 AM
Related advisories
- chalk-plus-ts@1.0.4
- polymarket-trading-developer-tool@0.1.2
- eslint-jest@4.0.6
- eslint-jest@4.0.5
- api-changelly@19.2.11
- @marketfront/actualordersnippetpopup@7.0.0
- @marketfront/basemarkettemplate@7.0.0
- @marketfront/advertisingdevtool@7.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.