MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromised Solana web3.js npm releases expose downstream applications to malicious code

On 03/12/2024, a publish-access account for the legitimate @solana/web3.js package was compromised, allowing unauthorized versions 1.95.6 and 1.95.7 to be published to npm with code capable of stealing private-key material from applications that directly handled keys. The malicious distribution window lasted roughly five hours before patched version 1.95.8 replaced the affected releases.

70

Estimated severity

70 / 100

95

Source reliability

95 / 100

Approximate Date

03/12/2024

Targeted Company

SOLANA FOUNDATION

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Switzerland

CHE

Other Affected Countries

No other affected countries reported

Target country

Switzerland

Affected countries

Switzerland

Impacted regions

No information

Operational Impact

Duration

0.21 days

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Account takeoverSoftware supply chain compromise

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.