Cointime

Download App
iOS & Android

Supply Chain Attack Detected in Solana's web3.js Library

Cointime Official

From socket dev by Sarah Gooding

A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular @solana/web3.js library, which receives more than ~350,000 weekly downloads on npm. These compromised versions contain injected malicious code that is designed to steal private keys from unsuspecting developers and users, potentially enabling attackers to drain cryptocurrency wallets.

What We Know So Far:

  • Affected Versions: 1.95.6 and 1.95.7 of the @solana/web3.js library on npm.
  • Malicious Activity: The injected code captures private keys and transmits them to a hardcoded address.
  • Linked Wallet: The activity has been traced to the Solana address FnvLGtucz4E1ppJHRTev6Qv4X7g8Pw6WPStHCcbAKbfx.
  • Cause: Believed to be the result of a social engineering/phishing attack targeting maintainers of the official Web3.js open source library maintained by Solana.

Potential Impact:

  • Developers integrating these versions into their projects risk exposing their private keys.
  • Users of applications relying on the compromised library may have their wallets drained if private keys are compromised.

Immediate Actions for Developers:

  1. Check Dependencies: Audit your projects for any usage of @solana/web3.js and identify if versions 1.95.6 or 1.95.7 are in use.
  2. Rollback or Update: Downgrade to a safe version prior to 1.95.6 or update to version 1.95.8, which was released to remove the injected code.
  3. Verify Code: Manually inspect your node_modules directory and dependency trees for suspicious modifications.
  4. Revoke Access: Regenerate compromised keys and revoke permissions as needed.

How to Check If Your Application Is Affected

You can use Socket's free tools to check if your code is affected:

  • Install Socket and run a scan with the CLI (with socket scan create .). This is an easy way to see if you’re affected in a local repository.
  • Install the free Socket for GitHub app, which will let you find out if any repos across your organization are using the affected version (though repos won’t be scanned until there is a new commit in each repo on the default branch).

This is a developing story and we will update as we get more information.

Update:

npm has moved swiftly to remove the affected versions.

12/4/2024 - 6:50PM EST: In a post on Bluesky, Datadog cloud security researcher Christophe Tafani-Dereeper highlighted that the backdoor in v1.95.7 includes an "addToQueue" function designed to exfiltrate private keys using seemingly-legitimate CloudFlare headers.

"This function is strategically injected into various legitimate code paths that access the private key," Tafani-Dereeper explained.

He also noted that the associated domain (sol-rpc[.]xyz) was registered on November 22 via NameSilo and is currently hosted behind CloudFlare, although the C2 is currently down.

Impact of the Supply Chain Attack#

At 6:12PM on December 3, Anza, a Solana focused research and development firm, disclosed that a publish-access account was compromised, allowing the threat actor to steal private key material and drain funds from dapps, like bots, that handle private keys directly.

Anza clarified that the attack should not affect non-custodial wallets, because they don't expose private keys during transactions.

This is not an issue with the Solana protocol itself, but with a specific JavaScript client library and only appears to affect projects that directly handle private keys and that updated within the window of 3:20pm UTC and 8:25pm UTC on Tuesday, December 2, 2024.

Anza recommends developers who suspect they were compromised to rotate any suspect authority keys, including multisigs, program authorities, and server keypairs.

Mert Mumtaz, CEO of Helius Labs, a Solana development tools company, estimated the damage from this attack to be roughly $130K. Decrypt projected the breach led to $160K in stolen assets, including SOL tokens and other crypto assets, based on Solscan data for the hardcoded wallet.

Mumtaz reports that most major wallets and apps were not affected or not using the compromised versions, including Phantom, Backpack, Coinbase, Exodus, and Kamino. Apps that were not blindly upgrading to the latest versions from npm during the few hours when the compromised versions were live, are likely not affected by the incident. These packages were promptly removed from npm to mitigate the damage to developers and apps relying on Solana's web3.js library.

Comments

All Comments

Recommended for you

  • BTC Surpasses $84,000

    Market data shows that BTC has surpassed $84,000, currently priced at $84,004, with a 24-hour decline of 0.25%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Falls Below $84,000

    Market data shows that BTC has fallen below $84,000, currently priced at $83,988.06, with a 24-hour increase of 0.52%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Falls Below $2700

    Market data shows that ETH has fallen below $2700, currently priced at $2699.7, with a 24-hour increase of 1.95%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $85,000

    Market data shows that BTC has surpassed $85,000, currently priced at $85,000.02, with a 24-hour increase of 1.72%. The market is highly volatile, so please ensure proper risk management.

  • ETH Surpasses $2700

    Market data shows that ETH has surpassed $2700, currently priced at $2700.14, with a 24-hour increase of 1.23%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Yushu Technology's Wang Xingxing: Key to Breakthrough in Embodied Intelligence Lies in Solving Millimeter-Level Error Issues

    On September 25, the 5th Global Digital Trade Expo was held in Hangzhou, where Wang Xingxing, founder of Yushu Technology, delivered a keynote speech titled "From Machinery to Intelligence - The Evolutionary Theory of Embodied Future." Wang stated that the embodied intelligence industry may soon experience a critical breakthrough similar to that of ChatGPT. He believes that when robots can complete approximately 80% of tasks through voice interaction and embodied intelligence capabilities in about 80% of unfamiliar environments, the industry will enter a critical phase of large-scale application. He pointed out that the ability for robots to understand and execute specific tasks based on voice commands has already made breakthroughs last year, but the industry still faces a core technological bottleneck, namely the precise matching issue between artificial intelligence models and the real physical world. Wang noted that currently, robots still have a few millimeters of error during actual operations, which limits their stability and reliability in complex environments. "In the future, whoever can solve this problem will fundamentally resolve the issues with robots."

  • Swissquote Analyst Warns AI Narrative is a Core Pillar of US Stocks, Potential Break Could Trigger Significant Correction

    On September 25, Ipek Ozkardeskaya, a senior analyst at Swissquote Bank, stated that broad market indices and retirement funds are now deeply tied to the AI wave, with technology stocks accounting for about 40% of the S&P 500 index. She pointed out that the market capitalization weight of just three chip manufacturers makes up over 25% of the MSCI Emerging Markets Index. Ozkardeskaya indicated that AI has become the 'core pillar' of the market, and this pillar 'must not show any cracks.' She believes that, in the short term, the US stock market will continue to be supported by seasonal factors, and the current market uptrend may extend until the end of the year. However, she also warned that the worst-case scenario would be a shake in the investment logic surrounding AI, which could undermine market confidence in the AI narrative, potentially triggering a significant market correction.

  • U.S. Stock Index Futures Turn Positive; Chip Stocks Rally in After-Hours Trading

    On September 25, U.S. stock index futures rose into positive territory, with Nasdaq futures up 0.36%. In after-hours trading, storage and semiconductor stocks saw widespread gains, with AMD, Intel, and SanDisk all rising by 2%.

  • NEAR Partners with Ondo to Launch 20 Tokenized US Stocks and ETFs

    On September 25, according to Cryptonews, NEAR Protocol and Ondo Finance have launched trading for tokenized US stocks and ETFs on near.com, with an initial offering of 20 assets including Nvidia, Tesla, Apple, Microsoft, Amazon, as well as SPY and QQQ. Eligible users can deposit using over 30 supported stablecoins or other crypto assets, with NEAR Intents serving as the cross-chain distribution layer, allowing similar assets to be routed to connected wallets and DeFi protocols in the future. Purchases are settled in USDon, which is backed 1:1 by US dollars in brokerage accounts, and completed via atomic swaps. This product is not available to US persons; the overall Ondo platform has launched over 100 assets, with NEAR initially offering only one-fifth of that.

  • Meta Achieves Best Monthly Performance Since 2013, Market Value Approaches $2 Trillion

    On September 25, Meta is experiencing a strong rebound driven by AI expectations, with the popularity of its personal AI assistant Muse serving as a significant catalyst for this rally. The company's stock had faced considerable pressure earlier this year, but it quickly rebounded in September. As of September 24, the stock price has risen approximately 36% this month, marking the strongest single-month performance since 2013, with its market value nearing $2 trillion, just about 1% away from this milestone.