216.73.216.6

PyPI package targets Solana developers

· Published 13/05/2025 21:01 · Modified 21/05/2025 19:34

Export JSON

Essential information

Published
13/05/2025 21:01
Modified
21/05/2025 19:34
Tags
2025-05-13 blockchain cryptocurrency exfiltration infostealer open-source pypi solana solana-token supply chain attack
Related entities
8 techniques (mitre), 1 malware, 2 others

Description

A malicious package named has been discovered targeting developers. The package, downloaded over 600 times, attempts to steal source code and developer secrets from infected machines. It uses suspicious behaviors like communicating with IP addresses on non-standard ports and reading from files to exfiltrate data to a remote server. This attack is part of a broader trend of supply chain attacks on projects, with 23 such campaigns identified in 2024 alone. The package name was previously used for another malicious module, suggesting possible reuse by the same threat actors. Developers are urged to monitor for suspicious activity in open source and third-party software to prevent such supply chain attacks.

External references