Cointime

Download App
iOS & Android

Supply Chain Attack Detected in Solana's web3.js Library

Cointime Official

From socket dev by Sarah Gooding

A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library, which receives more than ~350,000 weekly downloads on npm. These compromised versions contain injected malicious code that is designed to steal private keys from unsuspecting developers and users, potentially enabling attackers to drain cryptocurrency wallets.

What We Know So Far:

  • Affected Versions: 1.95.6 and 1.95.7 of the @solana/web3.js library on npm.
  • Malicious Activity: The injected code captures private keys and transmits them to a hardcoded address.
  • Linked Wallet: The activity has been traced to the Solana address FnvLGtucz4E1ppJHRTev6Qv4X7g8Pw6WPStHCcbAKbfx.
  • Cause: Believed to be the result of a social engineering/phishing attack targeting maintainers of the official Web3.js open source library maintained by Solana.

Potential Impact:

  • Developers integrating these versions into their projects risk exposing their private keys.
  • Users of applications relying on the compromised library may have their wallets drained if private keys are compromised.

Immediate Actions for Developers:

  1. Check Dependencies: Audit your projects for any usage of @solana/web3.js and identify if versions 1.95.6 or 1.95.7 are in use.
  2. Rollback or Update: Downgrade to a safe version prior to 1.95.6 or update to version 1.95.8, which was released to remove the injected code.
  3. Verify Code: Manually inspect your node_modules directory and dependency trees for suspicious modifications.
  4. Revoke Access: Regenerate compromised keys and revoke permissions as needed.

How to Check If Your Application Is Affected

You can use Socket's free tools to check if your code is affected:

  • Install Socket and run a scan with the CLI (with socket scan create .). This is an easy way to see if you’re affected in a local repository.
  • Install the free Socket for GitHub app, which will let you find out if any repos across your organization are using the affected version (though repos won’t be scanned until there is a new commit in each repo on the default branch).

This is a developing story and we will update as we get more information.

Update:

npm has moved swiftly to remove the affected versions.

12/4/2024 - 6:50PM EST: In a post on Bluesky, Datadog cloud security researcher Christophe Tafani-Dereeper highlighted that the backdoor in v1.95.7 includes an "addToQueue" function designed to exfiltrate private keys using seemingly-legitimate CloudFlare headers.

"This function is strategically injected into various legitimate code paths that access the private key," Tafani-Dereeper explained.

He also noted that the associated domain (sol-rpc[.]xyz) was registered on November 22 via NameSilo and is currently hosted behind CloudFlare, although the C2 is currently down.

Impact of the Supply Chain Attack#

At 6:12PM on December 3, Anza, a Solana focused research and development firm, disclosed that a publish-access account was compromised, allowing the threat actor to steal private key material and drain funds from dapps, like bots, that handle private keys directly.

Anza clarified that the attack should not affect non-custodial wallets, because they don't expose private keys during transactions.

This is not an issue with the Solana protocol itself, but with a specific JavaScript client library and only appears to affect projects that directly handle private keys and that updated within the window of 3:20pm UTC and 8:25pm UTC on Tuesday, December 2, 2024.

Anza recommends developers who suspect they were compromised to rotate any suspect authority keys, including multisigs, program authorities, and server keypairs.

Mert Mumtaz, CEO of Helius Labs, a Solana development tools company, estimated the damage from this attack to be roughly $130K. Decrypt projected the breach led to $160K in stolen assets, including SOL tokens and other crypto assets, based on Solscan data for the hardcoded wallet.

Mumtaz reports that most major wallets and apps were not affected or not using the compromised versions, including Phantom, Backpack, Coinbase, Exodus, and Kamino. Apps that were not blindly upgrading to the latest versions from npm during the few hours when the compromised versions were live, are likely not affected by the incident. These packages were promptly removed from npm to mitigate the damage to developers and apps relying on Solana's web3.js library.

Comments

All Comments

Recommended for you

  • Amazon Shares Surge 15.2%, Biggest Gain Since 2012

    On July 31, Amazon shares surged 15.2% to $271.255 per share, marking their biggest gain since 2012, with a total market value of $2.92 trillion.

  • US Treasury Secretary Bessent Vows to Track Down Iranian Assets Globally for Terror Victims

    US Treasury Secretary Bessent said the US will actively track down Iranian assets worldwide to ensure compensation funds for victims of Iran-backed terrorist activities. Bessent stated that the US government's military and economic blockade measures against the Iranian regime will continue and will not be relaxed. (Jinshi)

  • Apple Plunges Nearly 10%, Q4 Revenue Guidance Misses Expectations

    On July 31, Apple (AAPL.US) plunged nearly 10% to $300.33, marking its biggest drop since April 2025. In terms of fundamentals, Apple's third-fiscal-quarter revenue rose approximately 16% year-over-year to $109.42 billion, slightly above analyst expectations. Among the details, product revenue came in at $78.68 billion, beating the expected $77.25 billion. However, services revenue—a key driver of its valuation re-rating in recent years—totaled $30.74 billion, missing the consensus estimate of $31.36 billion. Additionally, Greater China revenue reached $18.82 billion, with year-over-year growth slowing to 22%, also below analysts' forecast of $19.58 billion. During the earnings call, Apple guided fourth-fiscal-quarter revenue growth in the range of 9% to 11%, overall below the 12.1% analysts had expected. CFO Parekh noted that component supply constraints would impact iPhone, Mac, and iPad businesses in the fourth fiscal quarter, with currency fluctuations also constraining growth.

  • Three Fed Officials Back Rate Hike, Hawkish Pressure Builds

    On July 31, three Federal Reserve policymakers said that dissenting votes in favor of a rate hike this week stemmed from stubborn inflationary pressures, highlighting rising internal pressure on Fed Chair Warsh to act. In statements released Friday morning, Hammack and Kashkari said they worry that although the current round of price increases may stem from short-term factors such as President Trump's tariff policies and the Iran war, the inflation situation already warrants Fed action. Logan also joined in, saying that even if inflation cools, if the Fed does not raise rates, inflation is unlikely to fully fall back to the Fed's 2% target; without any policy constraints, inflation could continue to run above target until an unexpected shock occurs. Kashkari said that if inflation remains persistently stubborn, he might support a series of rate hikes, not just a single increase, to prevent inflation from becoming further entrenched. He said: "A series of small policy adjustments may be preferable to waiting for developments to unfold and ultimately having to take more forceful action." Hammack said that if the Fed does not tighten policy, price increases could continue to accelerate. She said: "Inflation has been stubbornly above 2% for more than five years, and I have no confidence that it will return to our target on its own." (Jin Shi)

  • US 10-Year Treasury Yield Rises to 4.7388%, Highest Since January 2025

    On July 31, the US 10-year Treasury yield rose to 4.7388%, the highest level since January 2025.

  • Spot Gold Intraday Decline Widens to 2%, at $4,021.08 per Ounce

    On July 31, spot gold's intraday decline widened to 2%, reported at $4,021.08 per ounce.

  • BTC Falls Below $63,000

    Market数据显示,BTC has fallen below $63,000, currently reported at $62,985.99, with a 24-hour decline of 2.99%. Market volatility is significant, please exercise risk control.

  • Fed's Logan: Leaning Toward 25 Basis Point Rate Hike

    On July 31, Federal Reserve Governor Logan said she leans toward a 25 basis point rate hike, believing inflation has not yet entered a sustainable path back to the Fed's 2% target. Logan stated that taking moderate action now would reduce the risk of needing more aggressive tightening in the future, while emphasizing that the Fed cannot rely on unexpected shocks to achieve its inflation target.

  • Fed's Logan: Taking Modest Actions Now Reduces Likelihood of Needing Stronger Action Later

    On July 31, Dallas Fed President Lorie Logan said that taking modest actions in the near term would reduce the likelihood of needing to take stronger action in the future.

  • Philadelphia Semiconductor Index Erases 5% Gain, Turns Lower

    On July 31, U.S. chip and semiconductor stocks rapidly weakened, with the Philadelphia Semiconductor Index wiping out a 5% gain and turning lower. Micron Technology, which had risen 6%, is now down 4.2%. SanDisk, which had gained nearly 10%, is now down over 6%. SK Hynix and Seagate Technology, which had risen over 8%, are now down 2%. TSMC, which had gained 4%, is now down nearly 1%.