Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Supply Chain Attack Detected in Solana's web3.js Library - S...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
711
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent supply chain attack targeted versions 1.95.6 and 1.95.7 of the @solana/web3.js library, widely used in the Solana ecosystem, by injecting malicious code designed to steal private keys, potentially enabling attackers to siphon funds from cryptocurrency wallets. This attack, suspected to result from a phishing assault on the library's maintainers, compromised accounts and led to significant financial losses, with estimates of around $130K to $160K in stolen assets. The malicious activity was traced to a specific Solana address and involved a strategically injected function that used legitimate-looking CloudFlare headers to exfiltrate private keys. Developers using the affected versions are urged to audit their projects, downgrade or update to secure versions, and regenerate any compromised keys. Despite the breach, major wallets and apps such as Phantom and Coinbase were reportedly unaffected, as they did not use the compromised versions. Prompt removal of the affected versions from npm has been part of the mitigation efforts, and the attack has been highlighted by security experts to emphasize the importance of cautious dependency management.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.