MAL-2026-10902
Dashboard / Malicious Package / MAL-2026-10902
MAL-2026-10902
Summary: Malicious code in solana-web3-patched (npm)
Details: Source: amazon-inspector (e99e6f959c8df3e2933c860ba3d36dc5dbbd27d97a69a3e97a5a7feaf7e24899) Package name 'solana-web3-patched' resembles the legitimate '@solana/web3.js' library and is published as an unscoped lookalike at version 1.0.0. The bundled lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of child_process import, fetch/POST/GET calls, and shell utilities (curl, ping) within the same files. Pattern matches alone in a minified/bundled file cannot conclusively distinguish legitimate Solana RPC client behavior from exfiltration, and traced-code corroboration is unavailable. Given the typosquat-shaped name plus presence of child_process + outbound HTTP + curl/ping primitives in the bundle, the package warrants human review before allowing into installer environments. A reviewer should verify whether the child_process and curl/ping references are reachable at require/install time and whether any hardcoded destinations are attacker-controlled.
References: https://research.jfrog.com/post/solana-fakefix, https://www.npmjs.com/package/solana-web3-patched/v/1.0.0, https://github.com/advisories/GHSA-p492-8qvf-j49c
Affected packages
Package
Name: solana-web3-patched
Purl: pkg:npm/solana-web3-patched
Affected ranges
Type: N/A
Events:
