MAL-2026-5861

    Dashboard / Malicious Package / MAL-2026-5861

    MAL-2026-5861

    Published: 16 Jun 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-8gg8-q73f-wv82

    Summary: Malicious code in solana-mev-bot (npm)

    Details: Source: amazon-inspector (e65516d3e042858742ebfee878ff2de6361994ce0155dcbf53c8e0f24cd5fafb) bot.js performs a hardcoded HTTPS GET to api.telegram.org's bot sendMessage endpoint, transmitting host fingerprint data collected via os.hostname(), os.userInfo(), and process.platform. The file also imports child_process and reads from the filesystem (fs.existsSync / fs.readFileSync) alongside the network exfiltration primitive. The destination is an attacker-operated Telegram bot, used as an exfiltration channel to siphon installer host identity and likely credential/wallet material from disk. The package name impersonates a Solana MEV trading utility to lure crypto users into running it.

    Affected packages

    Package

    Name: solana-mev-bot

    Purl: pkg:npm/solana-mev-bot

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0