SlowMist: GitHubs popular Solana tool hides a trap for stealing coins
Odaily News According to the monitoring of the SlowMist security team, on July 2, a victim said that he had used an open source project hosted on GitHub the day before - zldp2002/solana-pumpfun-bot, and then his encrypted assets were stolen. According to SlowMist analysis, in this attack, the attacker induced users to download and run malicious code by disguising as a legitimate open source project (solana-pumpfun-bot). Under the cover of increasing the popularity of the project, the user ran the Node.js project with malicious dependencies without any defense, resulting in the leakage of wallet private keys and theft of assets. The entire attack chain involves multiple GitHub accounts to operate in coordination, which expands the scope of dissemination, enhances credibility, and is extremely deceptive. At the same time, this type of attack uses social engineering and technical means, and it is difficult to fully defend within the organization. SlowMist recommends that developers and users be highly vigilant against GitHub projects of unknown origin, especially when it comes to wallet or private key operations. If you really need to run and debug, it is recommended to run and debug in an independent machine environment without sensitive data.
You may also like

Lily Liu, the chair of the Solana Foundation, shouted "Don't waste time on crypto," is the crypto industry really dead?

The little deer live by the water and grass

The world belongs to Chinese people who speak English

Why Stop at 126K? Michael Saylor Breaks Down BTC Stagnation and Retail Absence Truth

Virtuals Protocol's inaugural Titan project: ROBO aims to give a wallet to a robot

Stablecoin Latest Report: Actual Distribution and Circulation Much More Notable Than Supply

Paradigm's New Arithmetic: When Crypto Can't Hold 12.7 Billion, AI Becomes the Answer

Wintermute Founder: In the Lost Cryptocurrency Market, What Can We Still Do?

$1.3 Billion Debt: BitDeer Faces Tough Battle

Anthropic's IPO Gamble: At the Most Unlikely Moment, It Chose to Say No

Paradigm's Math Problem: $12.7 Billion, Too Big for a Single Crypto Fund

Ethereum Unveils Scaling Roadmap, What's Different This Time?

Anthropic Ban Wave, OpenAI $100 Billion Funding Controversy: What Is the Overseas Crypto Community Talking About Today?

Morning News | OpenAI receives $110 billion investment; Solana launches Solana Payments; M0, MoonPay, and PayPal jointly launch PYUSDx

Bloomberg: A Romanian Presidential Election Intervened by Crypto Traders

Founders Fund, Pantera, and Franklin Templeton join Sentient's "Arena" to stress test enterprise-level AI agents

Why Retail Is Shifting From Crypto to Equities: Will They Return?
Retail traders are exiting the crypto market and gravitating towards equities. Bitcoin saw a notable reduction in spot…

Canton Crypto Network vs. XRP: Understanding DTCC’s Strategic Approach to Infrastructure and Liquidity
Key Takeaways Canton Network and XRP serve distinct roles in blockchain technology: Canton for asset tokenization and atomic…