MAL-2026-10902

    Dashboard / Malicious Package / MAL-2026-10902

    MAL-2026-10902

    Published: 20 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-p492-8qvf-j49c

    Summary: Malicious code in solana-web3-patched (npm)

    Details: Source: amazon-inspector (e99e6f959c8df3e2933c860ba3d36dc5dbbd27d97a69a3e97a5a7feaf7e24899) Package name 'solana-web3-patched' resembles the legitimate '@solana/web3.js' library and is published as an unscoped lookalike at version 1.0.0. The bundled lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of child_process import, fetch/POST/GET calls, and shell utilities (curl, ping) within the same files. Pattern matches alone in a minified/bundled file cannot conclusively distinguish legitimate Solana RPC client behavior from exfiltration, and traced-code corroboration is unavailable. Given the typosquat-shaped name plus presence of child_process + outbound HTTP + curl/ping primitives in the bundle, the package warrants human review before allowing into installer environments. A reviewer should verify whether the child_process and curl/ping references are reachable at require/install time and whether any hardcoded destinations are attacker-controlled.

    Affected packages

    Package

    Name: solana-web3-patched

    Purl: pkg:npm/solana-web3-patched

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-10902 | CVE-DB