News

Backdoor slipped into popular code library, drains ~$155k from digital wallets Solana-web3.js code library drains private keys, giving access to user wallets.
Damage likely limited to those running bots with private key access Malware-poisoned versions of the widely used JavaScript library @solana/web3.js were distributed via the npm package registry ...
Supply chain attack: Solana web3.js library was infected with malicious code Unknown attackers have equipped Solana's JavaScript SDK with malicious code to steal private keys.