Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in solana-key-utils (npm)

0
Critical
Published: 07/14/2026 (07/14/2026, 13:58:15 UTC)
Source: GCVE Database
Product: solana-key-utils

Description

The solana-key-utils npm package versions 1.0.0 through 1.0.3 contain malicious code that, upon being required, waits 37 seconds before decoding and writing a hidden JavaScript payload to the user's cache directory. This payload is then executed detached from the original process and scheduled to run persistently every 12 hours via platform-specific mechanisms on Linux, Windows, and macOS. The package name and test fixture disguise the malicious payload, enabling persistent unauthorized code execution on affected systems.

Affected software

npmghsa
solana-key-utils
Affected versions
=1.0.2=1.0.1=1.0.3=1.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 12:43:52 UTC

Technical Analysis

The solana-key-utils package (versions 1.0.0, 1.0.1, 1.0.2, and 1.0.3) contains embedded malicious code that activates on require(). It delays execution for 37 seconds, reads a base64-encoded JavaScript payload disguised as a test fixture, decodes it, writes it to ~/.cache-db/.node-sync/syncd.js with restricted permissions, and launches it as a detached process. The payload establishes persistence by installing scheduled tasks: a crontab entry on Linux, a Windows scheduled task named 'WinNodeSync', and a macOS LaunchAgent configured to run every 12 hours. This mechanism allows the attacker persistent code execution independent of the original package usage, effectively compromising the host.

Potential Impact

This malicious package enables persistent remote code execution on the affected system by installing scheduled tasks that run a hidden JavaScript payload every 12 hours. This can lead to unauthorized control over the host, potential data compromise, and further system exploitation. The persistence mechanisms span all major desktop platforms, increasing the attack surface and difficulty of detection and removal.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should immediately uninstall the solana-key-utils package versions 1.0.0 through 1.0.3 and remove any scheduled tasks or persistence mechanisms created by the package (crontab entries, Windows scheduled tasks named 'WinNodeSync', and macOS LaunchAgents at ~/Library/LaunchAgents/com.apple.syncd.plist). Monitor for and delete the dropped payload file at ~/.cache-db/.node-sync/syncd.js. Check vendor advisories or trusted sources for updates or official fixes. Avoid using this package until a safe version is released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10591
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a577ed268715ace43b3f7b4

Added to database: 07/15/2026, 12:36:34 UTC

Last enriched: 07/15/2026, 12:43:52 UTC

Last updated: 07/27/2026, 04:02:11 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses