SlowMist: GitHubs popular Solana tool hides a trap for stealing coins
Odaily News According to the monitoring of the SlowMist security team, on July 2, a victim said that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of increasing the popularity of the project, the user ran the Node.js project with malicious dependencies without any defense, resulting in the leakage of wallet private keys and theft of assets. The entire attack chain involves multiple GitHub accounts to operate in coordination, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses social engineering and technical means, and it is difficult to fully defend within the organization. SlowMist recommends that developers and users be highly vigilant against GitHub projects of unknown origin, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.
You may also like

Lil Pump’s Bold Solana Tattoo Move: Rapper Dumps SOL Tokens After Inking Blockchain Name on Forehead
As of August 14, 2025, the world of crypto and celebrity antics continues to collide in unexpected ways.…

Fairdesk Crypto Exchange Shuts Down Amid Regulatory Pressures: A Look Back on Its Closure
As of today, August 14, 2025, the cryptocurrency landscape continues to evolve rapidly, with past events like the…

Bitcoin Faces Resistance at $125K, Signaling Potential Consolidation Before Surge to $140K
As of today, August 14, 2025, the cryptocurrency market is buzzing with activity, and Bitcoin is at the…

XRP Price Chart Signals Potential 75% Surge as SEC Concludes Lawsuit Against Ripple
As of today, August 14, 2025, XRP continues to navigate a key legal obstacle with an injunction limiting…

Kalshi Election Betting Contracts Surge After Major Court Victory
The innovative prediction marketplace Kalshi has rolled out over a dozen contracts linked to U.S. political events since…
Gainers
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Services:[email protected]