MAL-2026-10902
Malicious code in solana-web3-patched (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (e99e6f959c8df3e2933c860ba3d36dc5dbbd27d97a69a3e97a5a7feaf7e24899) Package name 'solana-web3-patched' resembles the legitimate '@solana/web3.js' library and is published as an unscoped lookalike at version 1.0.0. The bundled lib/index.cjs.js and lib/index.esm.js contain co-occurring patterns of child_process import, fetch/POST/GET calls, and shell utilities (curl, ping) within the same files. Pattern matches alone in a minified/bundled file cannot conclusively distinguish legitimate Solana RPC client behavior from exfiltration, and traced-code corroboration is unavailable. Given the typosquat-shaped name plus presence of child_process + outbound HTTP + curl/ping primitives in the bundle, the package warrants human review before allowing into installer environments. A reviewer should verify whether the child_process and curl/ping references are reachable at require/install time and whether any hardcoded destinations are attacker-controlled.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for solana-web3-patched (npm). Pin to a known-safe version or switch to an alternative.