MAL-2026-10899

    Dashboard / Malicious Package / MAL-2026-10899

    MAL-2026-10899

    Published: 20 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-vc55-fvgr-m9jv

    Summary: Malicious code in solana-web3-fixed (npm)

    Details: Source: amazon-inspector (2d36c0e75143828e4a93135d0c54fb34dd6e75588a493ade663a1fa4b231230c) Package name 'solana-web3-fixed' resembles a fix-branded variant of the legitimate '@solana/web3.js' library, a pattern frequently used in lure/typosquat campaigns. The bundled main files (lib/index.cjs.js and lib/index.esm.js) trigger multiple keyword co-occurrence patterns associated with credential exfiltration: require('child_process') alongside POST/GET fetch calls and shell utilities (curl, ping). Without traced-code corroboration, these patterns cannot be conclusively attributed to either malicious behavior or legitimate Solana RPC / build tooling composition inside a minified bundle. Given the high-risk naming pattern (fix-branded variant of a top-tier crypto library) and the stacked critical static signals across both CJS and ESM bundles, this should be reviewed by a human before being trusted in any installer pipeline.

    Affected packages

    Package

    Name: solana-web3-fixed

    Purl: pkg:npm/solana-web3-fixed

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0