A spear-phishing attack targeted maintainers with publish access to the @solana namespace. Malicious versions were published with a backdoor stealing private keys via CloudFlare headers. At least $160,000 in SOL cryptocurrency was confirmed stolen. Compromised versions were available for ~5 hours.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects versions without source commits
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS; SOURCE_MALFORMED_METADATA detects versions without source commits |
| Sonatype (Nexus) | Partial | Limited ecosystem coverage for this attack |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |