
A supply chain attack has compromised Solana's popular web3.js npm library, which has over 400,000 weekly downloads. Malicious versions 1.95.6 and 1.95.7 of the library were released, containing a backdoor in the 'addToQueue' function that allowed attackers to steal private keys. This breach has reportedly resulted in approximately $184,000 in stolen assets, including SOL tokens and other cryptocurrencies, according to Solscan data. The attack, which began on December 2, 2024, targeted various entities, including bots, custodial services, and decentralized applications (dApps). Solana developers are currently addressing the fallout from this incident as they work to secure the library and protect users' assets.
Official Solana JavaScript library compromised in supply chain attack, at least $184,000 taken December 2, 2024 https://t.co/j2lLg77VZS
Solana blockchain's popular web3.js npm package backdoored to steal keys, funds https://t.co/fJ4UbQIxLI
Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin Access: https://t.co/56F9KSS7OL by The Hacker News #infosec #cybersecurity #technology #news