Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Researchers discover a backdoor in the popular Solana Web3.js npm library
Global Security

Researchers discover a backdoor in the popular Solana Web3.js npm library

AdminBy AdminDecember 4, 2024No Comments3 Mins Read
Web3.js npm Library
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 4, 2024Ravi LakshmananAn attack on the supply chain

npm Web3.js library

Cybersecurity researchers warn of attack on software supply chains targeting popular @solana/web3.js npm library, which included the promotion of two malicious versions capable of harvesting users’ private keys in order to drain their cryptocurrency wallets.

The attack was discovered in versions 1.95.6 and 1.95.7. Both of these versions are no longer available for download from the npm registry. The package is widely used, attracting more than 400,000 downloads every week.

“These compromised versions contain embedded malware that is designed to steal private keys from unsuspecting developers and users, potentially allowing attackers to empty cryptocurrency wallets,” Socket. said in the report.

@solana/web3.js is an npm package that can be used for to interact with the Solana JavaScript Software Development Kit (SDK) for building Node.js and web applications.

Cyber ​​security

According to security researcher Datadog Christophe Taffani-Deriper“the backdoor inserted in v1.95.7 adds an ‘addToQueue’ function that steals the private key via the seemingly legitimate CloudFlare headers” and that “calls to this function are then inserted into various places that (legitimately) access the private key” .

The command and control server (C2) to which the keys were transferred (“sol-rpc(.)xyz”) is currently down. It was registered on November 22, 2024 at the domain registrar NameSilo.

It is suspected that the developers of the npm package fell victim to a phishing attack that allowed threat actors to take control of accounts and publish fake versions.

“The publish access account has been compromised for @solana/web3.js, a JavaScript library commonly used by Solana dApps,” said Steven Luscher, one of the library’s maintainers. said in the release notes for version 1.95.8.

“This allowed an attacker to publish unauthorized and malicious packages that were modified to allow him to steal private key material and extract funds from dApps such as bots that process private keys directly. Non-custodian wallets should not be affected by this issue, as they typically do not disclose private keys during transactions.”

Lüscher also noted that the incident only affects projects that directly handle private keys and that were updated between 15:20 UTC and 20:25 UTC on December 2, 2024.

Users relying on @solana/web3.js as a dependency are encouraged to update to the latest version as soon as possible and optionally change their authorization keys if they suspect they have been compromised.

The disclosure comes days after Socket warned about a rogue Solana-themed npm package called solana-systemprogram-utils, which is designed to slyly redirect user funds to an attacker-controlled wallet address in 2% of transactions.

Cyber ​​security

“Code cleverly disguises its intentions while functioning normally 98% of the time,” Socket Research Group said. “This design minimizes suspicion, but still allows an attacker to withdraw funds.”

It also follows the discovery of npm packages such as crypto-keccak, crypto-jsonwebtoken and crypto-bignumber posing as legitimate libraries but containing code to extract credentials and cryptocurrency wallet data, again highlighting how threat actors continue abuse of trust developers place in the open source ecosystem.

“The malware threatens individual developers by stealing their credentials and wallet data, which can lead to direct financial losses,” security researcher Kirill Boychanka noted. “For organizations, compromised systems create vulnerabilities that can spread throughout the enterprise environment, allowing widespread exploitation.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.