Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'mal-2026-10904'

View all threats tagged with 'mal-2026-10904'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-10904

Threats Tagged 'mal-2026-10904'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in solana-web3-v1 (npm)
0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (073f4c1e75630bbf1c535a334f4d7f233a73439240bc22e69bac0e926c8c58a0) Package name closely mirrors the widely-used @solana/web3.js Solana SDK while being published under an unrelated, unscoped name. The bundled lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of require('child_process'), fetch/POST/GET calls, and shell utilities (curl, ping) within the same minified bundle. Without traced execution, it cannot be confirmed from these matches alone whether the network calls are user-facing RPC client functionality (consistent with a Solana SDK) or a hardcoded exfiltration channel, nor whether the child_process/curl/ping usage is dead/library code or reachable on import. Given the strong name-confusion against a high-traffic SDK target, the combination of HTTP + child_process + shell-tool keywords inside a single bundle, and the lack of clean traced evidence, this should not be auto-allowed; a human should verify the destinations, the reachability of the child_process paths, and whether the package is a legitimate fork/mirror or a confusion-attack lure.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-10904
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses