Switzerland
CHE
On 03/12/2024, a publish-access account for the legitimate @solana/web3.js package was compromised, allowing unauthorized versions 1.95.6 and 1.95.7 to be published to npm with code capable of stealing private-key material from applications that directly handled keys. The malicious distribution window lasted roughly five hours before patched version 1.95.8 replaced the affected releases.
Estimated severity
70 / 100
Source reliability
95 / 100
Approximate Date
03/12/2024
Targeted Company
SOLANA FOUNDATION
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Switzerland
CHE
No other affected countries reported
Target country
Switzerland
Affected countries
Impacted regions
No information
Duration
0.21 days
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone