Solana FakeFix Campaign Targets Developers with Malicious Packages

Solana FakeFix Campaign Targets Developers with Malicious Packages

First seen 13 Jun 2026, 00:26 UTC CybersecuritynewsSocprime 85% similarity 71.2

Article Content

Browse articles
ThreatCluster

A malicious campaign named Solana FakeFix is targeting Solana developers by deploying 25 typosquatted npm and PyPI packages. These packages are designed to steal sensitive information such as wallet keys, cloud credentials, and SSH keys upon installation. The malware exploits package lifecycle execution and import-time hooks, allowing it to operate undetected. Some variants also function as backdoors, utilizing Telegram for command-and-control operations. JFrog Security researchers have identified the operation and recommend immediate removal of the affected packages from development environments. Organizations are advised to rotate any exposed credentials and audit systems for persistence methods. The campaign poses a significant risk to developers and their projects, emphasizing the need for heightened security measures.

Key Points: • 25 malicious npm and PyPI packages are targeting Solana developers. • The malware steals sensitive information upon installation and can act as a backdoor. • Organizations must remove affected packages and rotate exposed credentials immediately.

ThreatCluster AI How this analysis works

Timeline

2026-06-12
Solana FakeFix campaign identified
JFrog Security researchers uncovered a campaign using malicious packages to steal developer secrets.
Socprime
2026-06-12
Malicious packages detailed
The campaign includes 25 typosquatted packages that exploit developers' environments to retrieve sensitive data.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story