MAL-2026-10900

    Dashboard / Malicious Package / MAL-2026-10900

    MAL-2026-10900

    Published: 20 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-rf7g-mf44-5m44

    Summary: Malicious code in solana-web3-fork (npm)

    Details: Source: amazon-inspector (912cb41aa6b78cf62207dbf95f7d6247238483a800fa9bc6edd9b9d9f7819364) Package name appears to fork or imitate the well-known @solana/web3.js library. Bundled files lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of child_process usage, fetch/POST/GET calls, and shell utilities (curl, ping) within the same minified bundles. These keyword co-occurrences in a minified Solana SDK fork are concerning but cannot be conclusively distinguished from legitimate SDK behavior (RPC calls, build tooling) without semantic verification of the bundle. Specific hardcoded attacker C2 endpoints, credential-theft paths, or install-time lifecycle hooks have not been confirmed. Given the name-collision with a major crypto SDK and the suspicious pattern stacking in the bundle, manual review is warranted before allowing installer use.

    Affected packages

    Package

    Name: solana-web3-fork

    Purl: pkg:npm/solana-web3-fork

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0