Malicious code in solana-key-utils (npm)
The solana-key-utils npm package versions 1.0.0 through 1.0.3 contain malicious code that, upon being required, waits 37 seconds before decoding and writing a hidden JavaScript payload to the user's cache directory. This payload is then executed detached from the original process and scheduled to run persistently every 12 hours via platform-specific mechanisms on Linux, Windows, and macOS. The package name and test fixture disguise the malicious payload, enabling persistent unauthorized code execution on affected systems.
AI Analysis
Technical Summary
The solana-key-utils package (versions 1.0.0, 1.0.1, 1.0.2, and 1.0.3) contains embedded malicious code that activates on require(). It delays execution for 37 seconds, reads a base64-encoded JavaScript payload disguised as a test fixture, decodes it, writes it to ~/.cache-db/.node-sync/syncd.js with restricted permissions, and launches it as a detached process. The payload establishes persistence by installing scheduled tasks: a crontab entry on Linux, a Windows scheduled task named 'WinNodeSync', and a macOS LaunchAgent configured to run every 12 hours. This mechanism allows the attacker persistent code execution independent of the original package usage, effectively compromising the host.
Potential Impact
This malicious package enables persistent remote code execution on the affected system by installing scheduled tasks that run a hidden JavaScript payload every 12 hours. This can lead to unauthorized control over the host, potential data compromise, and further system exploitation. The persistence mechanisms span all major desktop platforms, increasing the attack surface and difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately uninstall the solana-key-utils package versions 1.0.0 through 1.0.3 and remove any scheduled tasks or persistence mechanisms created by the package (crontab entries, Windows scheduled tasks named 'WinNodeSync', and macOS LaunchAgents at ~/Library/LaunchAgents/com.apple.syncd.plist). Monitor for and delete the dropped payload file at ~/.cache-db/.node-sync/syncd.js. Check vendor advisories or trusted sources for updates or official fixes. Avoid using this package until a safe version is released.
Malicious code in solana-key-utils (npm)
Description
The solana-key-utils npm package versions 1.0.0 through 1.0.3 contain malicious code that, upon being required, waits 37 seconds before decoding and writing a hidden JavaScript payload to the user's cache directory. This payload is then executed detached from the original process and scheduled to run persistently every 12 hours via platform-specific mechanisms on Linux, Windows, and macOS. The package name and test fixture disguise the malicious payload, enabling persistent unauthorized code execution on affected systems.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The solana-key-utils package (versions 1.0.0, 1.0.1, 1.0.2, and 1.0.3) contains embedded malicious code that activates on require(). It delays execution for 37 seconds, reads a base64-encoded JavaScript payload disguised as a test fixture, decodes it, writes it to ~/.cache-db/.node-sync/syncd.js with restricted permissions, and launches it as a detached process. The payload establishes persistence by installing scheduled tasks: a crontab entry on Linux, a Windows scheduled task named 'WinNodeSync', and a macOS LaunchAgent configured to run every 12 hours. This mechanism allows the attacker persistent code execution independent of the original package usage, effectively compromising the host.
Potential Impact
This malicious package enables persistent remote code execution on the affected system by installing scheduled tasks that run a hidden JavaScript payload every 12 hours. This can lead to unauthorized control over the host, potential data compromise, and further system exploitation. The persistence mechanisms span all major desktop platforms, increasing the attack surface and difficulty of detection and removal.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately uninstall the solana-key-utils package versions 1.0.0 through 1.0.3 and remove any scheduled tasks or persistence mechanisms created by the package (crontab entries, Windows scheduled tasks named 'WinNodeSync', and macOS LaunchAgents at ~/Library/LaunchAgents/com.apple.syncd.plist). Monitor for and delete the dropped payload file at ~/.cache-db/.node-sync/syncd.js. Check vendor advisories or trusted sources for updates or official fixes. Avoid using this package until a safe version is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10591
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a577ed268715ace43b3f7b4
Added to database: 07/15/2026, 12:36:34 UTC
Last enriched: 07/15/2026, 12:43:52 UTC
Last updated: 07/27/2026, 04:02:11 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.