All vulnerabilities
CRITICALSupply chainexploited in the wild

NPM-SOLANA-WEB3JS-2024

npm · @solana/web3.js

Summary

On December 2-3, 2024, a @solana npm org member with publish access was spear-phished, allowing attackers to steal their credentials and 2FA code and publish malicious versions 1.95.6 and 1.95.7 of @solana/web3.js (over 450,000 weekly downloads). The backdoor added an addToQueue function that captured private keys used to sign transactions and exfiltrated them to a hardcoded attacker wallet address. The malicious versions were live for roughly five hours and resulted in the theft of over $190,000 in cryptocurrency before a clean version 1.95.8 was released.

References

Related vulnerabilities

All Supply chain →