5 Malicious npm Packages Typosquat Solana and Ethereum Libraries to Steal Private Keys
Blog post from Socket
Socket's Threat Research Team has uncovered a malicious campaign targeting cryptocurrency developers through five npm packages published under the account "galedonovan." These packages, which typosquat legitimate crypto libraries, are designed to exfiltrate private keys to a hardcoded Telegram bot, affecting both the Solana and Ethereum ecosystems. The packages operate by intercepting functions that handle private keys, silently sending them to the threat actor's Telegram group. While one package, "base_xd," was quickly unpublished, the others remain active, prompting takedown requests to npm. The campaign's unified command and control infrastructure, lack of obfuscation in some packages, and shared artifacts confirm a single threat actor behind the operation, posing significant risks to affected developers who must audit and remove these dependencies immediately.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 1 | 4,488 | 443 | 150 | +34% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.