Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Malicious PyPI Package Mimicking Solana Targets Developers

Malicious PyPI Package Mimicking Solana Targets Developers

A New Cybersecurity Threat Emerges

Kelly Cromley by Kelly Cromley
Aug 12, 2024
in Market News, News
Reading Time: 2 mins read
0
malicious pypi solana developers hack

Cybersecurity researchers recently uncovered a malicious package on the Python Package Index (PyPI) repository that pretends to be a library from the Solana blockchain platform. This package, however, is designed to steal sensitive information from its victims.

Researchers at Sonatype reported that the legitimate Solana Python API project is known as “solana-py” on GitHub and simply “solana” on PyPI. This minor naming discrepancy was exploited by a threat actor who published a fake “solana-py” project on PyPI. The malicious package, which attracted a total of 1,122 downloads since its publication on August 4, 2024, has since been removed from PyPI.

Exploiting Naming Discrepancies

The threat actor behind the rogue package took advantage of the similarity in names to deceive users searching for the legitimate “solana” package. The malicious library carried version numbers 0.34.3, 0.34.4, and 0.34.5, with the latest legitimate version being 0.34.3. This tactic was clearly intended to trick users into downloading the counterfeit package instead of the authentic one.

Moreover, the rogue package contained the actual code from the genuine Solana library but included additional malicious code in the “init.py” script. This code was responsible for harvesting Solana blockchain wallet keys from the system and exfiltrating this information to a domain operated by the threat actor, “treeprime-gen.hf[.]space.” This incident highlighted how cybercriminals are abusing legitimate services for malicious purposes.

Supply Chain Risk and Broader Implications

The attack posed a significant supply chain risk. Sonatype’s investigation revealed that legitimate libraries, such as “solders,” referenced “solana-py” in their PyPI documentation. This created a scenario where developers could mistakenly download the malicious “solana-py” package from PyPI, inadvertently broadening the attack surface.

The report indicated that if a developer using the legitimate “solders” PyPI package was misled by the documentation to download the typosquatted “solana-py” project, they would inadvertently introduce a crypto stealer into their application. This would not only compromise their secrets but also those of any user running the developer’s application.

Wider Context of Supply Chain Security

This disclosure came alongside reports from Phylum about identifying hundreds of thousands of spam npm packages on the registry containing markers of Tea protocol abuse. This campaign first came to light in April 2024. The supply chain security firm noted that the Tea protocol project was taking steps to address this problem. It emphasized the importance of not penalizing legitimate participants in the Tea protocol by reducing their remuneration due to system scammers. Additionally, npm has begun to remove some of these spammers, although the takedown rate does not match the new publication rate.

This incident underscored the critical importance of vigilance and thorough vetting in the open-source software community. The malicious “solana-py” package’s ability to infiltrate the PyPI repository and deceive users highlights the ongoing challenges in securing the software supply chain. Developers must be cautious and verify the authenticity of packages before integrating them into their projects. This vigilance is especially crucial in environments where slight variations in naming can lead to significant security breaches.

In conclusion, the discovery of the malicious “solana-py” package serves as a stark reminder of the evolving threats in the cybersecurity landscape. It emphasizes the need for continuous monitoring, improved security measures, and heightened awareness among developers to safeguard against such deceptive attacks. As the open-source community continues to grow and evolve, maintaining the integrity and security of software repositories like PyPI and npm remains a top priority.

Previous Post

Codexchain’s Journey: From Adversity to Innovation

Next Post

Kaku Finance Unveils Revolutionary Web3 Fintech Platform

Related Posts

ton blockchain

Telegram’s Cocoon Aims to Redefine Private, Decentralized AI

by Kelly Cromley
Dec 5, 2025
0

Telegram has introduced Cocoon, a decentralized AI computation network built on the TON blockchain, marking a significant move toward privacy-preserving...

base

Base–Solana Bridge Targets Smoother Crosschain Liquidity

by Kelly Cromley
Dec 5, 2025
0

Base has introduced a Chainlink-secured bridge connecting its Ethereum layer-2 network with the Solana blockchain, marking a notable step toward...

bullfrog power

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
0

Bullfrog Power has introduced a new initiative aimed at strengthening transparency in environmental reporting by issuing tokenized sustainability certificates on...

titan trading platform

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
0

Titan Trading Platform has revealed a strategic collaboration with Zeni.io, a provider specializing in data infrastructure tailored for AI agents....

agi open network

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025
0

AGI Open Network (AON), a prominent decentralized ecosystem for building AI agents, has entered a strategic partnership with Infiblue World,...

N3XT

Blockchain-Driven N3XT Bank Promises Instant 24/7 Dollar Payments

by Kelly Cromley
Dec 4, 2025
0

A new player in financial services, N3XT, has formally launched with the goal of reshaping business-to-business payments through blockchain technology....

Next Post
kaku finance web3 fintech platform

Kaku Finance Unveils Revolutionary Web3 Fintech Platform

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

ton blockchain
Market News

Telegram’s Cocoon Aims to Redefine Private, Decentralized AI

by Kelly Cromley
Dec 5, 2025
base
Market News

Base–Solana Bridge Targets Smoother Crosschain Liquidity

by Kelly Cromley
Dec 5, 2025
bullfrog power
Market News

Bullfrog Power Launches Blockchain Tokens to Boost Sustainability Trust

by Kelly Cromley
Dec 5, 2025
titan trading platform
Market News

Titan–Zeni Alliance Aims to Elevate AI-Powered Crypto Trading

by Kelly Cromley
Dec 5, 2025
agi open network
Market News

AON and Infiblue World Unite to Advance AI-Driven Web3 Social Tools

by Kelly Cromley
Dec 5, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.