Solana users face malicious project attacks on GitHub, with a high risk of Private Key theft.

robot
Abstract generation in progress

Solana users encounter Private Key theft incidents, beware of malicious Open Source projects

In early July 2025, a Solana user discovered that their crypto assets had been stolen after using an open source project on GitHub. An investigation by the security team revealed a new type of attack method, which is worth the attention of cryptocurrency users.

The incident was triggered by the victim using an open-source project called "solana-pumpfun-bot." Although the project has received a high number of Stars and Forks on GitHub, its code updates are unusually concentrated and lack the characteristics of continuous maintenance.

Malicious NPM package steals Private Key, Solana users' assets are stolen

In-depth analysis reveals that the project relies on a suspicious third-party package "crypto-layout-utils". This package has been removed from the official NPM, and the version number does not match the official records. The attacker modified the package-lock.json file to point the download link of the dependency to a self-controlled GitHub repository.

Malicious NPM package steals Private Key, Solana users' assets are stolen

This malicious package is highly obfuscated, and its core function is to scan for sensitive files on the user's computer, particularly those related to cryptocurrency wallets and Private Keys, and upload this information to a server controlled by the attacker.

Malicious NPM package steals Private Key, Solana user assets are stolen

The investigation also found that the attackers may have controlled multiple GitHub accounts to distribute malware and enhance project credibility. They not only forked the original project but also inflated the star count to attract more users.

Malicious NPM package steals Private Key, Solana users' assets are stolen

In addition to "crypto-layout-utils", another malicious package named "bs58-encrypt-utils" was also used for similar attacks. This indicates that after the NPM officials took action, the attackers shifted to a strategy of directly distributing malicious packages.

Malicious NPM package steals Private Key, Solana users' assets are stolen

Funds tracking shows that a portion of the stolen assets flowed to a certain cryptocurrency exchange platform, which poses a challenge for the subsequent recovery of funds.

Malicious NPM package steals Private Key, Solana users' assets are stolen

This incident highlights the security threats faced by the Open Source community. Attackers successfully tricked users into running programs containing malicious code by disguising themselves as legitimate projects and using social engineering techniques. This form of attack is highly deceptive and difficult to completely prevent even within organizations.

Malicious NPM package steals Private Key, Solana user assets are stolen

To reduce risk, it is recommended that developers and users remain highly vigilant regarding GitHub projects of unknown origin, especially those involving wallet operations. If debugging is necessary, it is best to do so in an isolated environment to avoid sensitive information leakage.

Malicious NPM package steals Private Key, Solana users' assets are stolen

This incident serves as a reminder that in the rapidly evolving cryptocurrency space, security awareness and a cautious attitude are crucial. Users should remain vigilant at all times and treat any operations involving Private Key or sensitive information with caution.

Malicious NPM package steals Private Key, Solana user assets are stolen

Malicious NPM package steals Private Key, Solana user assets are stolen

Malicious NPM package steals Private Key, Solana users' assets are stolen

SOL-4.32%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 5
  • Repost
  • Share
Comment
0/400
GasFeeWhisperervip
· 07-19 06:59
It's the familiar script again...
View OriginalReply0
ForkTonguevip
· 07-17 23:18
Another sucker play machine?
View OriginalReply0
BearWhisperGodvip
· 07-17 23:18
Another one exploded, by 2025 it will be bought out.
View OriginalReply0
FloorPriceNightmarevip
· 07-17 23:12
Damn, this loss is huge.
View OriginalReply0
DaoGovernanceOfficervip
· 07-17 23:05
*sigh* predictable outcome based on nash equilibrium theory...
Reply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)