Home / Companies / Socket / Blog / Post Details
Content Deep Dive

5 Malicious npm Packages Typosquat Solana and Ethereum Libraries to Steal Private Keys

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
1,691
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team has uncovered a malicious campaign targeting cryptocurrency developers through five npm packages published under the account "galedonovan." These packages, which typosquat legitimate crypto libraries, are designed to exfiltrate private keys to a hardcoded Telegram bot, affecting both the Solana and Ethereum ecosystems. The packages operate by intercepting functions that handle private keys, silently sending them to the threat actor's Telegram group. While one package, "base_xd," was quickly unpublished, the others remain active, prompting takedown requests to npm. The campaign's unified command and control infrastructure, lack of obfuscation in some packages, and shared artifacts confirm a single threat actor behind the operation, posing significant risks to affected developers who must audit and remove these dependencies immediately.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 1 4,488 443 150 +34%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.