NPM Nightmare: Solana Web3.js Attack Drains Crypto Wallets Amid Phishing Fiasco

Beware the @solana/web3.js npm library! Two malicious versions, 1.95.6 and 1.95.7, have been discovered, designed to steal private keys and drain cryptocurrency wallets. The compromised versions are no longer available, but developers are urged to update immediately and rotate keys if needed. Remember, trust in open-source can sometimes be an open invitation!

Pro Dashboard

Hot Take:

Oh, the joys of open-source software! Where the only thing more abundant than free code is the opportunities for cybercriminals to ruin your day. This time, our trusty Solana library gets a malicious makeover, reminding us all that in the world of blockchain, even your code’s best friend might just be a backstabbing double agent.

Key Points:

  • Two malicious versions of the popular @solana/web3.js npm library were released targeting cryptocurrency wallets.
  • These versions, 1.95.6 and 1.95.7, have been removed from npm after being discovered.
  • The attack involved inserting backdoor code to steal private keys via CloudFlare headers.
  • It’s suspected the library maintainers were victims of a phishing attack.
  • Users are urged to update to the latest version and check for any potential security breaches.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?