Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads

Source: The Hacker News
Published: 2025-05-13 14:47
Fetched: 2025-05-13 16:19

Summary

Cybersecurity researchers have identified a malicious package on the Python Package Index (PyPI) that masqueraded as a tool for the Solana blockchain. The package, named 'solana-token', was designed to steal source code and developer secrets from unsuspecting users. Before its removal, the package was downloaded 761 times, posing a significant threat to developers who believed they were accessing legitimate resources. This incident underscores the critical need for developers to verify the authenticity of packages and remain vigilant against supply chain attacks. The event also highlights the importance of maintaining robust security measures to protect sensitive information and intellectual property.

LinkedIn Post

A malicious PyPI package posing as a Solana tool was discovered, stealing source code & developer secrets. Downloaded 761 times, it highlights the need for vigilance against supply chain attacks. #CyberSecurity #SupplyChainSecurity #Solana #PyPI

Content

Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that purports to be an application related to the Solana blockchain, but contains malicious functionality to steal source code and developer secrets. The package, named solana-token, is no longer available for download from PyPI, but not before it was downloaded 761 times. It was first