{"id":"MAL-2026-5788","summary":"Malicious code in @solana-labs/web3js (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d9bcfcd3a9b7eb540a36cb0d90a75c1e0c94cb5e78e265a85539608e3503a214)\nPackage name `@solana-labs/web3js` closely resembles the well-known `@solana/web3.js` library (different scope, missing dot in module name). The bundled `lib/index.cjs.js` and `lib/index.esm.js` are large minified blobs that include `require('child_process')`, `fetch(`, `POST`, `curl`, and `ping` strings, but the bundle is consistent in shape with a Solana web3 client SDK (RPC client, websocket subscriptions, JSON-RPC POST calls to user-configured endpoints). The keyword co-occurrence in a minified rollup bundle does not by itself confirm exfiltration: a JSON-RPC client legitimately POSTs to caller-supplied RPC URLs, and `child_process` references can come from bundled diagnostics or test utilities pulled into the rollup. No lifecycle script, top-level network beacon, or hardcoded attacker endpoint has been confirmed in the traced code. The primary concern is name/scope confusion against the official `@solana/web3.js` package, which carries real installer risk if developers select the wrong dependency. Routing to human review to (a) confirm whether the scope `@solana-labs` is an official Solana publisher or a lookalike, and (b) de-minify the relevant spans of the bundle to confirm the network calls are caller-configured RPC endpoints rather than a hardcoded C2.\n","aliases":["GHSA-pqhf-q5g8-6jpm"],"modified":"2026-09-01T11:31:28.503956429Z","published":"2026-06-15T17:15:14Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.8"],"id":"IN-MAL-2026-006571","import_time":"2026-06-15T17:22:51.267771759Z","modified_time":"2026-06-15T17:15:22Z","sha256":"154c1945271241882ae87bc62a23737410f47d3c4d5bba00512af9d5a56efe5b"},{"source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-006566","import_time":"2026-06-15T17:22:50.922747765Z","modified_time":"2026-06-15T17:15:19Z","sha256":"f5a3f5b21565aec159a2ed4715dd9616dbd9d8dcd43b08bb910193ee588da447"},{"versions":["1.0.8"],"id":"IN-MAL-2026-006572","import_time":"2026-06-15T17:22:51.361048729Z","modified_time":"2026-06-15T17:15:23Z","sha256":"fb19c365b2473db2041cdda820b816e8d425e9769e496677b23b8cdeb05872d0","source":"amazon-inspector"},{"id":"IN-MAL-2026-006562","import_time":"2026-06-15T17:22:50.605115454Z","modified_time":"2026-06-15T17:15:16Z","sha256":"2fc0c80b84dcef600acb67cb8160f0ab52a49ba8df7d4e580466124435d09bbf","source":"amazon-inspector","versions":["1.0.6"]},{"import_time":"2026-06-15T17:22:51.190598973Z","modified_time":"2026-06-15T17:15:21Z","sha256":"41785a71dc9811b8238c1766d0cbd16f34bfad11aa726fbfe2a3db4649246782","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-006570"},{"import_time":"2026-06-15T17:22:50.655806541Z","modified_time":"2026-06-15T17:15:17Z","sha256":"9916e7d1a9cf016186b532c3bb0a64848fe7a14da68984d9500a1fdb859bd972","source":"amazon-inspector","versions":["1.0.10"],"id":"IN-MAL-2026-006563"},{"sha256":"2c46f3a816002f536ea6d4f674c13988a2da8febe492682f65ec57720df1bc97","source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-006568","import_time":"2026-06-15T17:22:51.057633915Z","modified_time":"2026-06-15T17:15:20Z"},{"source":"amazon-inspector","versions":["1.0.10"],"id":"IN-MAL-2026-006565","import_time":"2026-06-15T17:22:50.801462174Z","modified_time":"2026-06-15T17:15:18Z","sha256":"36ca261f1c644617beb33a34e2530f5d4d8ded155cc385c65a5ac3dab7fd1123"},{"id":"IN-MAL-2026-006567","import_time":"2026-06-15T17:22:50.966270438Z","modified_time":"2026-06-15T17:15:20Z","sha256":"3b60338ab17ff69f9602cd9bf37ca9c25b1335c777bafbd3d4e2f2842d2e05a4","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-006561","import_time":"2026-06-15T17:22:50.563036753Z","modified_time":"2026-06-15T17:15:14Z","sha256":"a3eef5d02e2a799b24f5bc84c6fa4e57bc922a7182ba07145dc07c2ac5199238","source":"amazon-inspector","versions":["1.0.5"]},{"import_time":"2026-06-15T17:22:51.127216979Z","modified_time":"2026-06-15T17:15:21Z","sha256":"b79f799d106eaad2a09af8eac8b3ac64a46966e392ec423461facd26dc958705","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-006569"},{"modified_time":"2026-06-15T17:15:18Z","sha256":"e83ed61e8324ee03cada69746e85f8e90b42e95ea300fc73e5b47a7e6c214d51","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-006564","import_time":"2026-06-15T17:22:50.715837093Z"},{"versions":["1.0.0","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.10","1.98.103","1.98.105","1.98.107","1.98.108","1.98.109","1.98.110","1.98.111","1.98.112"],"id":"RLMA-2026-05469","import_time":"2026-07-20T13:14:42.602313167Z","modified_time":"2026-07-20T10:28:16Z","sha256":"c524c90dba42c1ac6e89db619ace6b6c668fdd1e9381020dc821b70050432f0b","source":"reversing-labs"},{"modified_time":"2026-08-05T05:16:41Z","sha256":"11d7621e5750d5dab20e6120bb0710589cc8fbf272c877dcb865a62515699890","source":"amazon-inspector","versions":["1.98.107"],"id":"IN-MAL-2026-012980","import_time":"2026-08-05T06:00:26.979712645Z"},{"import_time":"2026-08-05T06:00:22.810525233Z","modified_time":"2026-08-05T05:11:46Z","sha256":"333f4c79ecf1480fb1d8c5e9487a8086a73595c23f7b7b5e744f10a2ef3442f4","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-012945"},{"sha256":"80acd3581e663428e1adc113296abf5d266ffd1ec76d214185c45f16c4d3890b","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-012922","import_time":"2026-08-05T06:00:20.13335071Z","modified_time":"2026-08-05T05:08:30Z"},{"sha256":"d9bcfcd3a9b7eb540a36cb0d90a75c1e0c94cb5e78e265a85539608e3503a214","source":"amazon-inspector","versions":["1.98.110"],"id":"IN-MAL-2026-012973","import_time":"2026-08-05T06:00:26.248894396Z","modified_time":"2026-08-05T05:15:41Z"},{"import_time":"2026-08-05T06:00:22.48805587Z","modified_time":"2026-08-05T05:11:22Z","sha256":"0a797a2480183b8adcfcc43bb84c93fa32d1600f3bf472528ae78c1ad1edf55e","source":"amazon-inspector","versions":["1.98.105"],"id":"IN-MAL-2026-012942"},{"import_time":"2026-08-05T06:00:30.67546757Z","modified_time":"2026-08-05T05:20:56Z","sha256":"396327dd48d56cafc76b50112ae603fb6e5cd0d48969e415464ce096fd3d19b7","source":"amazon-inspector","versions":["1.98.112"],"id":"IN-MAL-2026-013010"},{"import_time":"2026-08-05T06:00:27.631304722Z","modified_time":"2026-08-05T05:17:33Z","sha256":"51684469e3db0855f1b8209984675d25ce32efea0bd7ef1276443b9af7d68cb0","source":"amazon-inspector","versions":["1.98.103"],"id":"IN-MAL-2026-012986"},{"id":"IN-MAL-2026-012979","import_time":"2026-08-05T06:00:26.872629985Z","modified_time":"2026-08-05T05:16:34Z","sha256":"a198098c537dcc1048633a5dd77b15c32fba01195492af4408f5ebdde86d5086","source":"amazon-inspector","versions":["1.98.108"]},{"sha256":"ad26022d456a92c7b1d76a371199145eb52b4d3a945082a5bca78a69ce749de3","source":"amazon-inspector","versions":["1.98.109"],"id":"IN-MAL-2026-012941","import_time":"2026-08-05T06:00:22.347362022Z","modified_time":"2026-08-05T05:11:13Z"},{"modified_time":"2026-08-05T05:15:23Z","sha256":"c6ddd8077eb6eb45a905fdb154068cba8362cbe7859429f1380efbc3ee7eed42","source":"amazon-inspector","versions":["1.98.111"],"id":"IN-MAL-2026-012971","import_time":"2026-08-05T06:00:26.049831472Z"},{"source":"reversing-labs","id":"RLUA-2026-05926","import_time":"2026-09-01T11:17:44.638694027Z","modified_time":"2026-08-24T16:31:02Z","sha256":"a5aabe9918fc93711ec12d57e1ddad288c0fd9599dba4f1272740d095c49da31"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.0"},{"type":"WEB","url":"https://research.jfrog.com/post/solana-fakefix"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.107"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.110"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.105"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.112"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.103"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.108"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.109"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@solana-labs/web3js/v/1.98.111"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pqhf-q5g8-6jpm"}],"affected":[{"package":{"name":"@solana-labs/web3js","ecosystem":"npm","purl":"pkg:npm/%40solana-labs/web3js"},"versions":["1.0.8","1.0.7","1.0.6","1.0.0","1.0.10","1.0.5","1.0.2","1.0.3","1.0.4","1.98.103","1.98.105","1.98.107","1.98.108","1.98.109","1.98.110","1.98.111","1.98.112"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"domains":["ifconfig.me","api.telegram.org"],"evidence_files":[{"path":"install.js","sha256":"e2f55065f26c6337b01f1e944df3f4c13a374b1b47ee8771a5e5680f9324c97e","tlsh":"3c4219bbf7a993b8c69a20785e1fb10b947b79134d84e144f85ce4826f6c24413a7cf9"},{"path":"package.json","sha256":"88b51b762faf72d4a4421e8767bbe6abcf6d9a9bb95ebf4fc11eda2108cdf91f","tlsh":"06e0d824ce504e7324c42e9a0d37814a1525481705047c0c7bd3908c8b4e63f28fa11e"}],"ips":["104.16.7.34"],"package_integrity":[{"filename":"web3js-1.0.8.tgz","hashes":{"sha1":"8a3386a122b028099102f59c0749dd0371a9d567","sha512_sri":"sha512-BVQTY7YZ7XTgcwC+YaPtN4jRS+d/tcMEX23LlTOmqty/Lz78BzMM8N0M9d+/7dd6d/UtirZahTB2gbyUmym8+g=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@solana-labs/web3js/MAL-2026-5788.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}