MAL-2026-5787

    Dashboard / Malicious Package / MAL-2026-5787

    MAL-2026-5787

    Published: 15 Jun 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-6465-92w6-mgp8

    Summary: Malicious code in @solana-labs/spl-toke (npm)

    Details: Source: amazon-inspector (8e2ec34996ab8cff20d9ba12cd9f5a8a75346c4e5e25d7c3fd5adc7bb7045f64) Package name `@solana-labs/spl-toke` is a likely confusion-attack against the well-known `@solana/spl-token` SPL token client (missing trailing `n`, different scope). The shipped `lib/index.cjs.js` and `lib/index.esm.js` bundles contain the keyword combinations `fetch(` / `POST` / `https.get` / `ping` that pattern-matched as potential C2 / exfiltration shapes, but tracing of the minified bundle did not complete and the literal destination URLs and trigger paths could not be confirmed in this run. The `ping` token may be benign (e.g. a websocket keepalive method or solana RPC ping helper) and the `fetch` calls may be ordinary RPC traffic — but neither has been verified, and combined with the typosquat-shaped name on a high-value scope (`@solana-labs/*` mimicking the official `solana-labs` GitHub org and the canonical `@solana/spl-token` package), this needs human review before installer use.

    Affected packages

    Package

    Name: @solana-labs/spl-toke

    Purl: pkg:npm/%40solana-labs/spl-toke

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    1.0.8
    1.0.10
    1.0.5
    1.0.6
    1.0.7
    1.0.2
    1.0.3
    1.0.4
    MAL-2026-5787 | CVE-DB