A sophisticated scam targeting Solana users has been uncovered, involving malicious code disguised as a legitimate trading bot on GitHub. This deceptive operation, which leveraged fake repositories and inflated engagement metrics, successfully stole cryptocurrency by harvesting user credentials and private keys. Blockchain security firm SlowMist exposed the scheme after a user reported stolen funds, highlighting a growing threat in software supply chain attacks.
Key Takeaways
-
Be wary of GitHub repositories, even those with high star and fork counts, as these can be manipulated.
-
Always verify the legitimacy of third-party packages and their sources, especially if they are not available on official registries.
-
This incident underscores the increasing threat of software supply chain attacks targeting cryptocurrency users, following similar schemes involving fake wallet extensions and credential-stealing code hosted on GitHub.
GitHub Scam Unveiled: Malicious Solana Bot Steals Crypto
Blockchain security firm SlowMist recently exposed a cunning scam on GitHub that utilized a seemingly legitimate Solana trading bot to steal cryptocurrency. The malicious repository, named solana-pumpfun-bot and hosted by the account "zldp2002," mimicked an open-source tool to harvest user credentials and private keys. The investigation began after a user reported their funds had been stolen.
The repository is currently deleted
How The Attack Unfolded
The attackers employed several deceptive tactics to ensnare victims:
-
Deceptive Repository: The
solana-pumpfun-botrepository appeared legitimate, boasting a high number of stars and forks, which SlowMist later identified as artificially inflated. -
Irregular Code Commits: All code commits across the repository's directories were made around the same time, lacking the consistent pattern typical of genuine, evolving projects.
-
Malicious Dependency: The project was Node.js-based and relied on a third-party package,
crypto-layout-utils. This package had been removed from the official NPM registry, yet victims were still able to download it, indicating the attacker was hosting it elsewhere.
The Malicious Package
Upon analysis, SlowMist researchers found the crypto-layout-utils package to be heavily obfuscated, making initial inspection difficult. After de-obfuscation, it was confirmed to be malicious. The package was designed to:
-
Scan local files for wallet-related content.
-
Identify and extract private keys.
-
Upload stolen data to a remote server.
Broader Attack Network
SlowMist's investigation revealed that the solana-pumpfun-bot was not an isolated incident. The attacker likely controlled a network of GitHub accounts used to:
-
Fork projects into malicious variations.
-
Distribute malware.
-
Artificially inflate fork and star counts across multiple repositories.
Some of these forked repositories incorporated another malicious package, bs58-encrypt-utils-1.0.3, created on June 12. This date is believed to mark the beginning of the attacker's distribution of malicious NPM modules and Node.js projects.
Sources
-
Solana Tool Steals Crypto From Its Users, Cointelegraph.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.