Malicious code in solana-web3-v1 (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (073f4c1e75630bbf1c535a334f4d7f233a73439240bc22e69bac0e926c8c58a0) Package name closely mirrors the widely-used @solana/web3.js Solana SDK while being published under an unrelated, unscoped name. The bundled lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of require('child_process'), fetch/POST/GET calls, and shell utilities (curl, ping) within the same minified bundle. Without traced execution, it cannot be confirmed from these matches alone whether the network calls are user-facing RPC client functionality (consistent with a Solana SDK) or a hardcoded exfiltration channel, nor whether the child_process/curl/ping usage is dead/library code or reachable on import. Given the strong name-confusion against a high-traffic SDK target, the combination of HTTP + child_process + shell-tool keywords inside a single bundle, and the lack of clean traced evidence, this should not be auto-allowed; a human should verify the destinations, the reachability of the child_process paths, and whether the package is a legitimate fork/mirror or a confusion-attack lure.
Malicious code in solana-web3-v1 (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (073f4c1e75630bbf1c535a334f4d7f233a73439240bc22e69bac0e926c8c58a0) Package name closely mirrors the widely-used @solana/web3.js Solana SDK while being published under an unrelated, unscoped name. The bundled lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of require('child_process'), fetch/POST/GET calls, and shell utilities (curl, ping) within the same minified bundle. Without traced execution, it cannot be confirmed from these matches alone whether the network calls are user-facing RPC client functionality (consistent with a Solana SDK) or a hardcoded exfiltration channel, nor whether the child_process/curl/ping usage is dead/library code or reachable on import. Given the strong name-confusion against a high-traffic SDK target, the combination of HTTP + child_process + shell-tool keywords inside a single bundle, and the lack of clean traced evidence, this should not be auto-allowed; a human should verify the destinations, the reachability of the child_process paths, and whether the package is a legitimate fork/mirror or a confusion-attack lure.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10904
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-x736-hhp7-jrh7"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a96f316acd9273b49e493c0
Added to database: 09/01/2026, 15:45:26 UTC
Last updated: 09/01/2026, 15:45:26 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.