Solana users suffer from Private Key theft, with malicious NPM packages as the mastermind.

Solana users encounter Private Key theft incident, malicious NPM package becomes the culprit

In early July 2025, a theft incident targeting Solana users caught the attention of security experts. The incident originated from the victim using an open-source project hosted on GitHub called solana-pumpfun-bot, after which their crypto assets were stolen.

Malicious NPM package steals Private Key, Solana users' assets are stolen

After the security team conducted an investigation, it was found that although the project had a high number of Stars and Forks, the code submission times were unusually concentrated, lacking the characteristics of continuous updates. Further analysis revealed that the project relied on a suspicious third-party package crypto-layout-utils, which has been removed from NPM by the official.

Malicious NPM package steals Private Key, Solana users' assets are stolen

Investigators found that the attacker replaced the download link for crypto-layout-utils in the package-lock.json file with a version from a GitHub repository. This version is highly obfuscated and is actually a malicious NPM package that can scan sensitive files on the user's computer and upload content containing Private Key to a server controlled by the attacker.

Malicious NPM package steals Private Key, Solana users' assets are stolen

The attacker may also have controlled multiple GitHub accounts to fork malicious projects and enhance their credibility. In addition to crypto-layout-utils, another malicious package named bs58-encrypt-utils was found to be involved in the attack.

Malicious NPM package steals Private Key, Solana users' assets are stolen

Through on-chain analysis tools, the security team traced some of the stolen funds to a certain trading platform.

Malicious NPM package steals Private Key, Solana users' assets are stolen

This incident highlights the hidden security risks in open-source projects. Attackers disguise themselves as legitimate projects and successfully lure users into running code with malicious dependencies through social engineering and technical means, resulting in private key leaks and asset losses.

Malicious NPM package steals Private Key, Solana users' assets are stolen

Security experts advise developers and users to remain highly vigilant about unknown GitHub projects, especially when it involves wallet or Private Key operations. If debugging is necessary, it is best to do so in a separate environment without sensitive data.

Malicious NPM Package Steals Private Key, Solana Users' Assets Are Stolen

This incident involves multiple malicious GitHub repositories and NPM packages, and the security team has compiled relevant information for reference. As attack methods continue to evolve, users should exercise extra caution when using open-source projects to guard against potential security threats.

Malicious NPM package steals Private Key, Solana users' assets are stolen

Malicious NPM package steals Private Key, Solana user assets are stolen

Malicious NPM package steals Private Key, Solana users' assets are stolen

Malicious NPM package steals Private Key, Solana users' assets are stolen

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
CryptoSourGrapevip
· 8h ago
Heh, seeing others being robbed, I actually feel a bit happy~
View OriginalReply0
RektButAlivevip
· 13h ago
suckers suffer every day
View OriginalReply0
OnChainDetectivevip
· 13h ago
Let's mention a few key data anomalies... forks are 43.2% higher than activity levels, and submission time concentration has reached 98.7%, which is very suspicious.
View OriginalReply0
ForumMiningMastervip
· 13h ago
A living fossil that has been stolen five times in three years.
View OriginalReply0
MetaMiseryvip
· 13h ago
Should have been stolen long ago
View OriginalReply0
NFTRegrettervip
· 14h ago
Stolen again, is that okay?
View OriginalReply0
SchrodingerWalletvip
· 14h ago
Who would dare to bet on SOL? I absolutely won't touch it.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)