menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Solana News

>

Malicious ...
source image

Securityaffairs

3d

read

372

img
dot

Image Credit: Securityaffairs

Malicious npm and PyPI target Solana Private keys to steal funds from victims’ wallets

  • Researchers have discovered malicious npm and PyPI packages designed to target Solana private keys and steal funds from victims' wallets.
  • The malicious npm packages allowed threat actors to exfiltrate Solana private keys via Gmail.
  • The attackers used names typosquatting popular libraries and exfiltrated the stolen information via Gmail's SMTP servers.
  • The packages are still live on npm despite experts' requests for removal, and two GitHub repositories were reported for supporting the malware campaign.

Read Full Article

like

22 Likes

For uninterrupted reading, download the app