Slow Fog: Popular Solana Tool on GitHub Hides Coin Theft Trap
PANews, July 3 news, according to the Slow Fog security team, on July 2, a victim reported that they used a project hosted on GitHub - zldp2002/solana-pumpfun-bot the day before, after which their encrypted assets were stolen. After analysis by Slow Fog, it was found that in this attack event, the attacker disguised themselves as a legitimate open source project (solana-pumpfun-bot), luring users to download and run malicious code. Under the guise of boosting the project's popularity, users unknowingly ran a Node.js project with malicious dependencies, leading to the leakage of their Wallet Private Key and asset theft. The entire attack chain involved multiple GitHub accounts working in coordination, expanding the scope of spread and enhancing credibility, making it highly deceptive. Meanwhile, such attacks utilize both social engineering and technical means, making it very difficult to completely defend against them within the organization.
Slow