Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (1,300)
  • Analysis (1,491)
  • Bitcoin (2,073)
  • Blockchain (1,202)
  • DeFi (1,419)
  • Ethereum (1,432)
  • Event (55)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (1,463)
  • Press Releases (1)
  • Reddit (724)
  • Regulation (1,363)
  • Security (1,964)
  • Thought Leadership (2)
  • Uncategorized (1)
  • Videos (41)
Hand picked
  • Bitcoin ATM Scams Costing Americans More Than $114 Million
  • Elon Musk supports Coinbase Warning: Bitcoin could replace the dollar in the middle of the American budget crisis
  • Retail fomo’d, pump.Fun profit: Where did the Altcoin season go?
  • Jpmorgan Chase should accept Bitcoin, Crypto ETF as a loan guarantee
  • Strategy to collect $ 250 million via Strd offering to buy more bitcoin
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Blockchain»Solana’s PyPI Library Users Steal Blockchain Wallet Keys
Blockchain

Solana’s PyPI Library Users Steal Blockchain Wallet Keys

August 14, 2024No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Python.jpg
Share
Facebook Twitter LinkedIn Pinterest Email


August 11, 2024Ravie LakshmananSupply Chain and Software Security

PyPI Library Not Allowed

Cybersecurity researchers have discovered a new malicious package on the Python Package Index (PyPI) repository that masquerades as a library for the Solana blockchain platform but is actually designed to steal victims’ secrets.

“The legitimate Solana Python API project is known as ‘solana-py’ on GitHub, but simply ‘solana’ on the Python software registry, PyPI,” Sonatype researcher Ax Sharma said in a report published last week. “This slight name difference was exploited by a malicious actor who published a ‘solana-py’ project on PyPI.”

The malicious package “solana-py” has attracted a total of 1,122 downloads since its release on August 4, 2024. It is no longer available for download on PyPI.

Cybersecurity

The most striking aspect of the library is that it had version numbers 0.34.3, 0.34.4, and 0.34.5. The latest version of the legitimate “solana” package is 0.34.3. This clearly indicates an attempt by the malicious actor to trick users searching for “solana” into inadvertently downloading “solana-py” instead.

Additionally, the malicious package borrows the real code from its counterpart, but injects additional code into the “__init__.py” script that is responsible for collecting Solana blockchain wallet keys from the system.

This information is then exfiltrated to a Hugging Face Spaces domain operated by the threat actor (“treeprime-gen.hf(.)space”), once again highlighting how threat actors abuse legitimate services for malicious purposes.

The attack campaign poses a risk to the supply chain as Sonatype’s investigation revealed that legitimate libraries like “solders” reference “solana-py” in their PyPI documentation, leading to a scenario where developers could have mistakenly downloaded “solana-py” from PyPI and expanded the attack surface.

“In other words, if a developer using the legitimate PyPI package “solders” in their application is misled (by the solders documentation) into falling for the typosquatted “solana-py” project, they would inadvertently introduce a crypto stealer into their application,” Sharma explained.

Cybersecurity

“This would steal not only their secrets, but also those of any user running the developer’s app.”

The revelation comes as Phylum said it had identified hundreds of thousands of spammy npm packages on the registry containing markers of Tea protocol abuse, a campaign that was first revealed in April 2024.

“The Tea Protocol project is taking steps to address this issue,” the supply chain security firm said. “It would be unfair for legitimate Tea Protocol participants to see their compensation reduced because others are scamming the system. Additionally, npm has started to remove some of these spammers, but the removal rate does not match the new release rate.”

Did you find this article interesting? Follow us on Twitter  and LinkedIn to read more of the exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAre ETH Bulls Preparing for a 100% Surge?
Next Article Coinbase Urges SEC to Reconsider Rule Change That Brings DeFi Under Its Jurisdiction: CNBC Crypto World

Related Posts

Blockchain

Bitcoin.com Transfers Newsus-Mexico accelerated by XDC-Bitso Blockchain Railin A strategic decision to revise the US-Mexico transfer flows, the XDC network united its forces with Bitso Business to deploy a blockchain …. 3 days ago, 3 days ago

June 4, 2025
Blockchain

Bitcoin.com NewScryptocity arrives: Kazakhstan to merge blockchain with the daily life of the life of daily life ignites a digital revolution with cryptocity, a daring experience to merge cryptocurrency in daily and economic life …. 1 day ago

June 4, 2025
Blockchain

Your short stop before being restored

June 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Kenya to Host Africa’s Leading Blockchain & Crypto Conference in June 2025 

May 30, 2025

Nairobi, Kenya – May 2025 — Africa’s rapidly evolving blockchain ecosystem will take center stage…

Event

Crypto Vision Conference 2025: A Breakthrough Day for Web3 in the Philippines

May 29, 2025

Makati City, Philippines — April 26, 2025 — The AIM Conference Center was a hub…

1 2 3 … 48 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Retail fomo’d, pump.Fun profit: Where did the Altcoin season go?

June 4, 2025

Stablecoin transmitter circulating $ 7,200,000,000 evaluation in the next IPO

June 4, 2025

Ethereum vs bitcoin? Vitalik says that BTC is gaining in simplicity and the number of nodes

June 4, 2025
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2025 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 104,828.09
ethereum
Ethereum (ETH) $ 2,610.81
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.20
bnb
BNB (BNB) $ 663.81
solana
Solana (SOL) $ 153.53
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.188433
tron
TRON (TRX) $ 0.274509
cardano
Cardano (ADA) $ 0.666293