A significant supply chain attack has impacted the Solana ecosystem, targeting the @solana/web3.js JavaScript library, a critical tool that developers rely on to create decentralized applications (dApps) on the Solana blockchain.
On December 2, hackers gained access to the account of a developer maintaining the @solana/web3.js library. It’s a tool that’s been downloaded more than 350,000 times weekly by Solana app developers.
Hackers compromised versions 1.95.6 and 1.95.7, embedding malicious code that exfiltrated private keys and drained funds. The breach led to $160,000 in stolen assets, including SOL ($144.03) tokens and other crypto assets, according to Solscan data.
Solana-focused development team Anza disclosed the breach on Tuesday saying it occurred when a publish-access account for the library on npm was compromised.
Earlier today, a publish-access account was compromised for @solana/web3.js, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker to publish unauthorized and malicious packages that were modified, allowing them to steal ...
















24h Most Popular







Utilities