Close Menu
  • Crypto News
  • Markets
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Technology
  • More
    • Crypto Prices – Latest from BTC, ETH & XRP
    • NFT
    • DeFi

Subscribe to Updates

Get the latest crypto news and updates directly to your inbox.

Trending

Non-compliant traders face steep fines

July 6, 2025

Elon Musk Launches America Party — Meme Coin AP Surges 120%

July 6, 2025

The Altcoin That Earned the Most Decentralized Application Revenue in the Last Three Months Has Been Revealed – It Made a Big Difference

July 6, 2025

How Brex is keeping up with AI by embracing the ‘messiness’

July 6, 2025

Orion leads altcoin rally as Solana falters below $150

July 6, 2025
Facebook X (Twitter) Instagram
  • Advertise
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianoru Русскийes Españolzh-CN 简体中文hi हिन्दीja 日本語
Crypto Observer
  • Crypto News

    Are Bitcoin Retail Traders Back In The Market? On-Chain Data Suggests So

    July 6, 2025

    Toncoin Hits 19-Day High Following UAE Visa Offer for $100K in Staked TON

    July 6, 2025

    Bitcoin Must Hold $106,000 And $98,000 To Avoid Breakdown

    July 6, 2025

    We Asked 4 AIs How High Ripple (XRP) Will Go in 2025: The Answers Might Shock You

    July 6, 2025

    Bitcoin’s True Value Is Higher Than $110,000, Expert Warns

    July 6, 2025
  • Markets
  • Bitcoin
  • Ethereum
  • XRP
  • Altcoins
  • Technology
  • More
    • Crypto Prices – Latest from BTC, ETH & XRP
    • NFT
    • DeFi
Facebook X (Twitter) Instagram
Crypto Observer
Home » Technology » Blockchain » Solana Tool Steals Crypto From Its Users
Blockchain

Solana Tool Steals Crypto From Its Users

Crypto Observer StaffBy Crypto Observer StaffJuly 4, 2025No Comments2 Mins Read
Facebook Twitter Pinterest Reddit Telegram Email LinkedIn Tumblr
Solana Tool Steals Crypto From Its Users
Share
Facebook Twitter LinkedIn Pinterest Email

A GitHub repository posing as a legitimate Solana trading bot has been exposed for reportedly hiding crypto-stealing malware.

According to a Friday report by blockchain security firm SlowMist, the now-deleted solana-pumpfun-bot repository hosted by account “zldp2002” mimicked a real open-source tool to harvest user credentials. SlowMist reportedly launched the investigation after a user found that their funds had been stolen on Thursday.

The malicious GitHub repository in question featured “a relatively high number of stars and forks,” SlowMist said. All code commits across all its directories were made about three weeks ago, with apparent irregularities and a lack of consistent pattern that, according to SlowMist, would indicate a legitimate project.

The project is Node.js-based and leverages the third-party package crypto-layout-utils as a dependency. “Upon further inspection, we found that this package had already been removed from the official NPM registry,” SlowMist said.

A screenshot of the now-deleted GitHub repository. Source: SlowMist

Related: Crypto theft campaign hits Firefox users with wallet clones

A suspicious NPM package

The package could no longer be downloaded from the official node package manager (NPM) registry, prompting investigators to question how the victim had downloaded the package. Investigating further, SlowMist discovered that the attacker was downloading the library from a separate GitHub repository.

After analyzing the package, SlowMist researchers found it to be heavily obfuscated using jsjiami.com.v7, making analysis harder. After de-obfuscation, investigators confirmed that it was a malicious package that scans local files, and if it detects wallet-related content or private keys, it would upload them to a remote server.

Related: North Korean hackers targeting crypto projects with unusual Mac exploit

More than a single repository

Further investigation by SlowMist revealed that the attacker likely controlled a batch of GitHub accounts. These accounts were used to fork projects into malicious variations, distributing malware while artificially inflating fork and star counts.

Multiple forked repositories exhibited similar features, with some versions incorporating another malicious package, bs58-encrypt-utils-1.0.3. This package was created on June 12, which is when SlowMist researchers said they believed the attacker began distributing malicious NPM modules and Node.js projects.

The incident is the latest in a string of software supply chain attacks targeting crypto users. In recent weeks, similar schemes have targeted Firefox users with fake wallet extensions and used GitHub repositories to host credential-stealing code.

Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec

Read the full article here

Crypto News cryptocurrency
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Vitalik Proposes 16.77M Gas Cap for Ethereum to Enhance Security

Vitalik Proposes 16.77M Gas Cap for Ethereum to Enhance Security

July 6, 2025
TON Offers UAE Golden Visa for $100K Staked, Promises 3–4% Yields

TON Offers UAE Golden Visa for $100K Staked, Promises 3–4% Yields

July 6, 2025
Secret Service Seizes $400M in Crypto, Builds One of World’s Largest Wallets

Secret Service Seizes $400M in Crypto, Builds One of World’s Largest Wallets

July 6, 2025
Mercado Bitcoin tokenizes $200 million in real-world assets on XRPL

Mercado Bitcoin tokenizes $200 million in real-world assets on XRPL

July 5, 2025
Add A Comment

Leave A Reply Cancel Reply

Subscribe to Updates

Get the latest crypto news and updates directly to your inbox.

Top Posts

Non-compliant traders face steep fines

July 6, 2025

Elon Musk Launches America Party — Meme Coin AP Surges 120%

July 6, 2025

The Altcoin That Earned the Most Decentralized Application Revenue in the Last Three Months Has Been Revealed – It Made a Big Difference

July 6, 2025
Advertisement
Demo

Crypto Observer is your one-stop website for the latest crypto news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Instagram
Crypto News

Toncoin Hits 19-Day High Following UAE Visa Offer for $100K in Staked TON

July 6, 2025

Bitcoin Must Hold $106,000 And $98,000 To Avoid Breakdown

July 6, 2025

We Asked 4 AIs How High Ripple (XRP) Will Go in 2025: The Answers Might Shock You

July 6, 2025
Get Informed

Subscribe to Updates

Get the latest crypto news and updates directly to your inbox.

Facebook X (Twitter)
  • Privacy Policy
  • Terms of use
  • Advertise with us | Publishing
  • Contact us
  • Crypto News – Press release
  • Newsletter sign up
  • Markets
  • Altcoins
  • Bitcoin
  • Crypto News
  • DeFi
  • Ethereum
  • Technology
  • Blockchain
  • AI
  • NFT
  • Thanks for joining us
© 2025 Crypto Observer. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.