Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Malicious PyPI Package Mimicking Solana Targets Developers

Malicious PyPI Package Mimicking Solana Targets Developers

A New Cybersecurity Threat Emerges

Kelly Cromley by Kelly Cromley
Aug 12, 2024
in Market News, News
Reading Time: 2 mins read
0
malicious pypi solana developers hack

Cybersecurity researchers recently uncovered a malicious package on the Python Package Index (PyPI) repository that pretends to be a library from the Solana blockchain platform. This package, however, is designed to steal sensitive information from its victims.

Researchers at Sonatype reported that the legitimate Solana Python API project is known as “solana-py” on GitHub and simply “solana” on PyPI. This minor naming discrepancy was exploited by a threat actor who published a fake “solana-py” project on PyPI. The malicious package, which attracted a total of 1,122 downloads since its publication on August 4, 2024, has since been removed from PyPI.

Exploiting Naming Discrepancies

The threat actor behind the rogue package took advantage of the similarity in names to deceive users searching for the legitimate “solana” package. The malicious library carried version numbers 0.34.3, 0.34.4, and 0.34.5, with the latest legitimate version being 0.34.3. This tactic was clearly intended to trick users into downloading the counterfeit package instead of the authentic one.

Moreover, the rogue package contained the actual code from the genuine Solana library but included additional malicious code in the “init.py” script. This code was responsible for harvesting Solana blockchain wallet keys from the system and exfiltrating this information to a domain operated by the threat actor, “treeprime-gen.hf[.]space.” This incident highlighted how cybercriminals are abusing legitimate services for malicious purposes.

Supply Chain Risk and Broader Implications

The attack posed a significant supply chain risk. Sonatype’s investigation revealed that legitimate libraries, such as “solders,” referenced “solana-py” in their PyPI documentation. This created a scenario where developers could mistakenly download the malicious “solana-py” package from PyPI, inadvertently broadening the attack surface.

The report indicated that if a developer using the legitimate “solders” PyPI package was misled by the documentation to download the typosquatted “solana-py” project, they would inadvertently introduce a crypto stealer into their application. This would not only compromise their secrets but also those of any user running the developer’s application.

Wider Context of Supply Chain Security

This disclosure came alongside reports from Phylum about identifying hundreds of thousands of spam npm packages on the registry containing markers of Tea protocol abuse. This campaign first came to light in April 2024. The supply chain security firm noted that the Tea protocol project was taking steps to address this problem. It emphasized the importance of not penalizing legitimate participants in the Tea protocol by reducing their remuneration due to system scammers. Additionally, npm has begun to remove some of these spammers, although the takedown rate does not match the new publication rate.

This incident underscored the critical importance of vigilance and thorough vetting in the open-source software community. The malicious “solana-py” package’s ability to infiltrate the PyPI repository and deceive users highlights the ongoing challenges in securing the software supply chain. Developers must be cautious and verify the authenticity of packages before integrating them into their projects. This vigilance is especially crucial in environments where slight variations in naming can lead to significant security breaches.

In conclusion, the discovery of the malicious “solana-py” package serves as a stark reminder of the evolving threats in the cybersecurity landscape. It emphasizes the need for continuous monitoring, improved security measures, and heightened awareness among developers to safeguard against such deceptive attacks. As the open-source community continues to grow and evolve, maintaining the integrity and security of software repositories like PyPI and npm remains a top priority.

Previous Post

Codexchain’s Journey: From Adversity to Innovation

Next Post

Kaku Finance Unveils Revolutionary Web3 Fintech Platform

Related Posts

unique network partners with tapnation for crypto rewards

TapNation Game Adds Seamless Crypto Rewards via Unique Network

by Kelly Cromley
Jul 12, 2025
0

Unique Network, a blockchain infrastructure firm operating within the Polkadot ecosystem, has successfully partnered with mobile game publisher TapNation to...

us bank

U.S. Bank Pioneers Blockchain-Based Trade Finance

by Kelly Cromley
Jul 12, 2025
0

U.S. Bank has become the first American financial institution to successfully carry out a fully digital trade finance transaction, signaling...

Zypto

Zypto Expands Real-World Crypto Utility with Visa Card and Mobile Top-Ups

by Kelly Cromley
Jul 12, 2025
0

Zypto, a rising player in blockchain-based fintech, has introduced two key services that significantly broaden the everyday utility of digital...

zeus network

Zeus Network Launches Bitcoin Airdrop for Solana Users

by Kelly Cromley
Jul 12, 2025
0

Zeus Network has unveiled a new Bitcoin Airdrop campaign aimed at active participants within the Solana blockchain ecosystem. This initiative...

circle partners with sei

Sei Blockchain Integrates Native USDC to Boost Multi-Chain Finance

by Kelly Cromley
Jul 12, 2025
0

Sei, a high-performance Layer-1 blockchain recognized for its speed and suitability in powering digital asset markets, is poised for a...

HSBC

HSBC Tests e-HKD+ Across Blockchains, Launches On-Chain Settlement

by Kelly Cromley
Jul 11, 2025
0

HSBC has made significant progress in its exploration of digital currency solutions by conducting a series of experimental trials involving...

Next Post
kaku finance web3 fintech platform

Kaku Finance Unveils Revolutionary Web3 Fintech Platform

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Central Bank of Saudi Arabia Teams Up with Ripple to Transform Cross-Border Settlements

    by Kelly Cromley
    Aug 17, 2023
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • GameStop’s Digital Transformation: Embracing Blockchain and NFTs

    by Kelly Cromley
    Feb 2, 2025

Recent News

unique network partners with tapnation for crypto rewards
Market News

TapNation Game Adds Seamless Crypto Rewards via Unique Network

by Kelly Cromley
Jul 12, 2025
us bank
Market News

U.S. Bank Pioneers Blockchain-Based Trade Finance

by Kelly Cromley
Jul 12, 2025
Zypto
Market News

Zypto Expands Real-World Crypto Utility with Visa Card and Mobile Top-Ups

by Kelly Cromley
Jul 12, 2025
zeus network
Market News

Zeus Network Launches Bitcoin Airdrop for Solana Users

by Kelly Cromley
Jul 12, 2025
circle partners with sei
Market News

Sei Blockchain Integrates Native USDC to Boost Multi-Chain Finance

by Kelly Cromley
Jul 12, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.
I Agree