Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Malicious PyPI Package Mimicking Solana Targets Developers

Malicious PyPI Package Mimicking Solana Targets Developers

A New Cybersecurity Threat Emerges

Kelly Cromley by Kelly Cromley
Aug 12, 2024
in Market News, News
Reading Time: 2 mins read
0
malicious pypi solana developers hack

Cybersecurity researchers recently uncovered a malicious package on the Python Package Index (PyPI) repository that pretends to be a library from the Solana blockchain platform. This package, however, is designed to steal sensitive information from its victims.

Researchers at Sonatype reported that the legitimate Solana Python API project is known as “solana-py” on GitHub and simply “solana” on PyPI. This minor naming discrepancy was exploited by a threat actor who published a fake “solana-py” project on PyPI. The malicious package, which attracted a total of 1,122 downloads since its publication on August 4, 2024, has since been removed from PyPI.

Exploiting Naming Discrepancies

The threat actor behind the rogue package took advantage of the similarity in names to deceive users searching for the legitimate “solana” package. The malicious library carried version numbers 0.34.3, 0.34.4, and 0.34.5, with the latest legitimate version being 0.34.3. This tactic was clearly intended to trick users into downloading the counterfeit package instead of the authentic one.

Moreover, the rogue package contained the actual code from the genuine Solana library but included additional malicious code in the “init.py” script. This code was responsible for harvesting Solana blockchain wallet keys from the system and exfiltrating this information to a domain operated by the threat actor, “treeprime-gen.hf[.]space.” This incident highlighted how cybercriminals are abusing legitimate services for malicious purposes.

Supply Chain Risk and Broader Implications

The attack posed a significant supply chain risk. Sonatype’s investigation revealed that legitimate libraries, such as “solders,” referenced “solana-py” in their PyPI documentation. This created a scenario where developers could mistakenly download the malicious “solana-py” package from PyPI, inadvertently broadening the attack surface.

The report indicated that if a developer using the legitimate “solders” PyPI package was misled by the documentation to download the typosquatted “solana-py” project, they would inadvertently introduce a crypto stealer into their application. This would not only compromise their secrets but also those of any user running the developer’s application.

Wider Context of Supply Chain Security

This disclosure came alongside reports from Phylum about identifying hundreds of thousands of spam npm packages on the registry containing markers of Tea protocol abuse. This campaign first came to light in April 2024. The supply chain security firm noted that the Tea protocol project was taking steps to address this problem. It emphasized the importance of not penalizing legitimate participants in the Tea protocol by reducing their remuneration due to system scammers. Additionally, npm has begun to remove some of these spammers, although the takedown rate does not match the new publication rate.

This incident underscored the critical importance of vigilance and thorough vetting in the open-source software community. The malicious “solana-py” package’s ability to infiltrate the PyPI repository and deceive users highlights the ongoing challenges in securing the software supply chain. Developers must be cautious and verify the authenticity of packages before integrating them into their projects. This vigilance is especially crucial in environments where slight variations in naming can lead to significant security breaches.

In conclusion, the discovery of the malicious “solana-py” package serves as a stark reminder of the evolving threats in the cybersecurity landscape. It emphasizes the need for continuous monitoring, improved security measures, and heightened awareness among developers to safeguard against such deceptive attacks. As the open-source community continues to grow and evolve, maintaining the integrity and security of software repositories like PyPI and npm remains a top priority.

Previous Post

Codexchain’s Journey: From Adversity to Innovation

Next Post

Kaku Finance Unveils Revolutionary Web3 Fintech Platform

Related Posts

ripple decentralized ledger

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
0

AMINA Bank, a Switzerland-based financial institution regulated by FINMA, has implemented Ripple Payments to improve how transactions flow between blockchain...

chainlink

MapleStory Universe Adopts Chainlink for Cross-Chain Gaming

by Kelly Cromley
Dec 13, 2025
0

MapleStory Universe, a blockchain-based gaming platform that enables players to create and monetize their own interactive experiences, has revealed its...

chainbase

Chainbase and OpenLedger Join Forces to Advance AI-Driven Web3

by Kelly Cromley
Dec 13, 2025
0

Chainbase, widely recognized for its omnichain data ecosystem designed for artificial intelligence, has announced a strategic collaboration with OpenLedger, a...

deepsafe partners with arc

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
0

DeepSafe, a decentralized cryptographic verification layer designed for Web3 and artificial intelligence ecosystems, has announced a formal alignment with ARC...

Italy

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025
0

Italy has taken a decisive step toward modernizing its capital markets with the launch of the country’s first minibond fully...

U.S. Securities and Exchange Commission (SEC)

SEC Approves DTCC Pilot to Tokenize U.S. Securities on Blockchains

by Kelly Cromley
Dec 12, 2025
0

The U.S. Securities and Exchange Commission has authorized a three-year pilot program allowing the clearinghouse responsible for nearly all equity...

Next Post
kaku finance web3 fintech platform

Kaku Finance Unveils Revolutionary Web3 Fintech Platform

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

ripple decentralized ledger
Market News

AMINA Bank Integrates Ripple to Modernize Cross-Border Payments

by Kelly Cromley
Dec 13, 2025
chainlink
Market News

MapleStory Universe Adopts Chainlink for Cross-Chain Gaming

by Kelly Cromley
Dec 13, 2025
chainbase
Market News

Chainbase and OpenLedger Join Forces to Advance AI-Driven Web3

by Kelly Cromley
Dec 13, 2025
deepsafe partners with arc
Market News

DeepSafe, ARC Matrix Launch Privacy-First Web3 Security Framework

by Kelly Cromley
Dec 12, 2025
Italy
Market News

Italy Debuts First Public-Chain Tokenized Minibond

by Kelly Cromley
Dec 12, 2025

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.