-= Per source details. Do not edit below this line.=-
Package name @solana-labs/web3js closely resembles the well-known @solana/web3.js library (different scope, missing dot in module name). The bundled lib/index.cjs.js and lib/index.esm.js are large minified blobs that include require('child_process'), fetch(, POST, curl, and ping strings, but the bundle is consistent in shape with a Solana web3 client SDK (RPC client, websocket subscriptions, JSON-RPC POST calls to user-configured endpoints). The keyword co-occurrence in a minified rollup bundle does not by itself confirm exfiltration: a JSON-RPC client legitimately POSTs to caller-supplied RPC URLs, and child_process references can come from bundled diagnostics or test utilities pulled into the rollup. No lifecycle script, top-level network beacon, or hardcoded attacker endpoint has been confirmed in the traced code. The primary concern is name/scope confusion against the official @solana/web3.js package, which carries real installer risk if developers select the wrong dependency. Routing to human review to (a) confirm whether the scope @solana-labs is an official Solana publisher or a lookalike, and (b) de-minify the relevant spans of the bundle to confirm the network calls are caller-configured RPC endpoints rather than a hardcoded C2.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-006571",
"import_time": "2026-06-15T17:22:51.267771759Z",
"modified_time": "2026-06-15T17:15:22Z",
"sha256": "154c1945271241882ae87bc62a23737410f47d3c4d5bba00512af9d5a56efe5b",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-006566",
"import_time": "2026-06-15T17:22:50.922747765Z",
"modified_time": "2026-06-15T17:15:19Z",
"sha256": "f5a3f5b21565aec159a2ed4715dd9616dbd9d8dcd43b08bb910193ee588da447",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-006572",
"import_time": "2026-06-15T17:22:51.361048729Z",
"modified_time": "2026-06-15T17:15:23Z",
"sha256": "fb19c365b2473db2041cdda820b816e8d425e9769e496677b23b8cdeb05872d0",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-006562",
"import_time": "2026-06-15T17:22:50.605115454Z",
"modified_time": "2026-06-15T17:15:16Z",
"sha256": "2fc0c80b84dcef600acb67cb8160f0ab52a49ba8df7d4e580466124435d09bbf",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-006570",
"import_time": "2026-06-15T17:22:51.190598973Z",
"modified_time": "2026-06-15T17:15:21Z",
"sha256": "41785a71dc9811b8238c1766d0cbd16f34bfad11aa726fbfe2a3db4649246782",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-006563",
"import_time": "2026-06-15T17:22:50.655806541Z",
"modified_time": "2026-06-15T17:15:17Z",
"sha256": "9916e7d1a9cf016186b532c3bb0a64848fe7a14da68984d9500a1fdb859bd972",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
},
{
"id": "IN-MAL-2026-006568",
"import_time": "2026-06-15T17:22:51.057633915Z",
"modified_time": "2026-06-15T17:15:20Z",
"sha256": "2c46f3a816002f536ea6d4f674c13988a2da8febe492682f65ec57720df1bc97",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-006565",
"import_time": "2026-06-15T17:22:50.801462174Z",
"modified_time": "2026-06-15T17:15:18Z",
"sha256": "36ca261f1c644617beb33a34e2530f5d4d8ded155cc385c65a5ac3dab7fd1123",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
},
{
"id": "IN-MAL-2026-006567",
"import_time": "2026-06-15T17:22:50.966270438Z",
"modified_time": "2026-06-15T17:15:20Z",
"sha256": "3b60338ab17ff69f9602cd9bf37ca9c25b1335c777bafbd3d4e2f2842d2e05a4",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-006561",
"import_time": "2026-06-15T17:22:50.563036753Z",
"modified_time": "2026-06-15T17:15:14Z",
"sha256": "a3eef5d02e2a799b24f5bc84c6fa4e57bc922a7182ba07145dc07c2ac5199238",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-006569",
"import_time": "2026-06-15T17:22:51.127216979Z",
"modified_time": "2026-06-15T17:15:21Z",
"sha256": "b79f799d106eaad2a09af8eac8b3ac64a46966e392ec423461facd26dc958705",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-006564",
"import_time": "2026-06-15T17:22:50.715837093Z",
"modified_time": "2026-06-15T17:15:18Z",
"sha256": "e83ed61e8324ee03cada69746e85f8e90b42e95ea300fc73e5b47a7e6c214d51",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "RLMA-2026-05469",
"import_time": "2026-07-20T13:14:42.602313167Z",
"modified_time": "2026-07-20T10:28:16Z",
"sha256": "c524c90dba42c1ac6e89db619ace6b6c668fdd1e9381020dc821b70050432f0b",
"source": "reversing-labs",
"versions": [
"1.0.0",
"1.0.2",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.10",
"1.98.103",
"1.98.105",
"1.98.107",
"1.98.108",
"1.98.109",
"1.98.110",
"1.98.111",
"1.98.112"
]
},
{
"id": "IN-MAL-2026-012980",
"import_time": "2026-08-05T06:00:26.979712645Z",
"modified_time": "2026-08-05T05:16:41Z",
"sha256": "11d7621e5750d5dab20e6120bb0710589cc8fbf272c877dcb865a62515699890",
"source": "amazon-inspector",
"versions": [
"1.98.107"
]
},
{
"id": "IN-MAL-2026-012945",
"import_time": "2026-08-05T06:00:22.810525233Z",
"modified_time": "2026-08-05T05:11:46Z",
"sha256": "333f4c79ecf1480fb1d8c5e9487a8086a73595c23f7b7b5e744f10a2ef3442f4",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-012922",
"import_time": "2026-08-05T06:00:20.13335071Z",
"modified_time": "2026-08-05T05:08:30Z",
"sha256": "80acd3581e663428e1adc113296abf5d266ffd1ec76d214185c45f16c4d3890b",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-012973",
"import_time": "2026-08-05T06:00:26.248894396Z",
"modified_time": "2026-08-05T05:15:41Z",
"sha256": "d9bcfcd3a9b7eb540a36cb0d90a75c1e0c94cb5e78e265a85539608e3503a214",
"source": "amazon-inspector",
"versions": [
"1.98.110"
]
},
{
"id": "IN-MAL-2026-012942",
"import_time": "2026-08-05T06:00:22.48805587Z",
"modified_time": "2026-08-05T05:11:22Z",
"sha256": "0a797a2480183b8adcfcc43bb84c93fa32d1600f3bf472528ae78c1ad1edf55e",
"source": "amazon-inspector",
"versions": [
"1.98.105"
]
},
{
"id": "IN-MAL-2026-013010",
"import_time": "2026-08-05T06:00:30.67546757Z",
"modified_time": "2026-08-05T05:20:56Z",
"sha256": "396327dd48d56cafc76b50112ae603fb6e5cd0d48969e415464ce096fd3d19b7",
"source": "amazon-inspector",
"versions": [
"1.98.112"
]
},
{
"id": "IN-MAL-2026-012986",
"import_time": "2026-08-05T06:00:27.631304722Z",
"modified_time": "2026-08-05T05:17:33Z",
"sha256": "51684469e3db0855f1b8209984675d25ce32efea0bd7ef1276443b9af7d68cb0",
"source": "amazon-inspector",
"versions": [
"1.98.103"
]
},
{
"id": "IN-MAL-2026-012979",
"import_time": "2026-08-05T06:00:26.872629985Z",
"modified_time": "2026-08-05T05:16:34Z",
"sha256": "a198098c537dcc1048633a5dd77b15c32fba01195492af4408f5ebdde86d5086",
"source": "amazon-inspector",
"versions": [
"1.98.108"
]
},
{
"id": "IN-MAL-2026-012941",
"import_time": "2026-08-05T06:00:22.347362022Z",
"modified_time": "2026-08-05T05:11:13Z",
"sha256": "ad26022d456a92c7b1d76a371199145eb52b4d3a945082a5bca78a69ce749de3",
"source": "amazon-inspector",
"versions": [
"1.98.109"
]
},
{
"id": "IN-MAL-2026-012971",
"import_time": "2026-08-05T06:00:26.049831472Z",
"modified_time": "2026-08-05T05:15:23Z",
"sha256": "c6ddd8077eb6eb45a905fdb154068cba8362cbe7859429f1380efbc3ee7eed42",
"source": "amazon-inspector",
"versions": [
"1.98.111"
]
},
{
"id": "RLUA-2026-05926",
"import_time": "2026-09-01T11:17:44.638694027Z",
"modified_time": "2026-08-24T16:31:02Z",
"sha256": "a5aabe9918fc93711ec12d57e1ddad288c0fd9599dba4f1272740d095c49da31",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"ifconfig.me",
"api.telegram.org"
],
"evidence_files": [
{
"path": "install.js",
"sha256": "e2f55065f26c6337b01f1e944df3f4c13a374b1b47ee8771a5e5680f9324c97e",
"tlsh": "3c4219bbf7a993b8c69a20785e1fb10b947b79134d84e144f85ce4826f6c24413a7cf9"
},
{
"path": "package.json",
"sha256": "88b51b762faf72d4a4421e8767bbe6abcf6d9a9bb95ebf4fc11eda2108cdf91f",
"tlsh": "06e0d824ce504e7324c42e9a0d37814a1525481705047c0c7bd3908c8b4e63f28fa11e"
}
],
"ips": [
"104.16.7.34"
],
"package_integrity": [
{
"filename": "web3js-1.0.8.tgz",
"hashes": {
"sha1": "8a3386a122b028099102f59c0749dd0371a9d567",
"sha512_sri": "sha512-BVQTY7YZ7XTgcwC+YaPtN4jRS+d/tcMEX23LlTOmqty/Lz78BzMM8N0M9d+/7dd6d/UtirZahTB2gbyUmym8+g=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@solana-labs/web3js/MAL-2026-5788.json"