Gmail For Exfiltration: Malicious npm Packages Target Solana...
Blog post from Socket
Researchers from Socket have identified several malicious npm packages that target Solana private keys by using Gmail for data exfiltration, which subsequently results in the draining of victims' wallets. These packages, including @async-mutex/mutex, dexscreener, solana-transaction-toolkit, and solana-stable-web-huks, utilize typosquatting to impersonate legitimate libraries but instead operate as malware. The threat actors behind these packages employ overlapping tactics and code to intercept private keys and use Gmail's SMTP servers for exfiltration because of its trusted status, making it less likely to be flagged by security systems. Despite petitions for their removal, these malicious packages continue to be available on npm, with some GitHub repositories amplifying the campaign by adding legitimacy to the packages. The attackers, using aliases such as "async-mutex" and "james0203," have incorporated scripts that not only steal Solana keys but also programmatically drain wallets, transferring up to 98% of their contents to an attacker-controlled Solana address. This attack highlights the importance of verifying package authenticity, auditing dependencies, and monitoring network traffic for unusual outbound connections, while solutions like the Socket GitHub app and CLI can provide real-time analysis to detect such threats during npm installations.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 1 | 6,457 | 1,307 | 242 | +28% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.