Socprime Solana FakeFix Campaign Targets Developers with Malicious Packages
Article Content
- •25 malicious npm and PyPI packages are targeting Solana developers.
- •The malware steals sensitive information upon installation and can act as a backdoor.
- •Organizations must remove affected packages and rotate exposed credentials immediately.
A malicious campaign named Solana FakeFix is targeting Solana developers by deploying 25 typosquatted npm and PyPI packages. These packages are designed to steal sensitive information such as wallet keys, cloud credentials, and SSH keys upon installation. The malware exploits package lifecycle execution and import-time hooks, allowing it to operate undetected. Some variants also function as backdoors, utilizing Telegram for command-and-control operations. JFrog Security researchers have identified the operation and recommend immediate removal of the affected packages from development environments. Organizations are advised to rotate any exposed credentials and audit systems for persistence methods. The campaign poses a significant risk to developers and their projects, emphasizing the need for heightened security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…