Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Weaponized PyPI Package Steals Solana Private Keys Via Supply Chain Attack

Weaponized PyPI Package Steals Solana Private Keys Via Supply Chain Attack

Posted on May 30, 2025May 31, 2025 By CWS

A classy provide chain assault focusing on Solana builders has compromised over 25,900 downloads by means of a weaponized Python bundle that silently steals cryptocurrency non-public keys throughout routine growth workflows.

The malicious marketing campaign, centered round a bundle known as “semantic-types,” represents a brand new evolution in software program provide chain threats by leveraging transitive dependencies and blockchain-based exfiltration strategies to bypass conventional safety controls.

The assault operates by means of a community of six interconnected PyPI packages, with semantic-types serving because the core malicious payload whereas 5 extra packages act as supply autos.

These secondary packages, together with solana-keypair, solana-publickey, solana-mev-agent-py, solana-trading-bot, and soltrade, all declare semantic-types as a dependency, making certain that putting in any of those seemingly legit Solana growth instruments mechanically downloads and executes the hidden malware.

Solana mev agent (Supply – Socket.dev)

The risk actor rigorously crafted polished documentation and linked the packages to legit Stack Overflow discussions and GitHub repositories to ascertain credibility inside the developer neighborhood.

Socket analysts recognized the malicious marketing campaign by means of behavioral evaluation that detected unauthorized cryptographic operations and suspicious dependency relationships.

The researchers famous that the risk actor employed a delayed activation technique, initially publishing benign variations of the packages in December 2024 earlier than introducing the malicious payload in late January 2025, permitting early adopters to construct belief earlier than the compromise occurred.

The marketing campaign’s timeline reveals a methodical strategy, with the malicious semantic-types model 0.1.5 introducing the payload on January 26, 2025, adopted by extra bundle releases to broaden the assault’s attain.

The monetary implications prolong past particular person builders, because the malware particularly targets Solana non-public keys that would present entry to cryptocurrency wallets and good contract credentials.

As soon as imported right into a growth setting, the malware silently captures each newly generated keypair and transmits the encrypted non-public key knowledge to the risk actor by means of legit Solana blockchain transactions, making the exfiltration seem as routine pockets exercise.

On the time of discovery, all six packages remained energetic on PyPI, doubtlessly persevering with to compromise extra developer environments and CI/CD pipelines.

Monkey Patching and Runtime Interception Mechanism

The technical sophistication of this assault lies in its use of monkey patching, a dynamic Python method that replaces features at runtime with out modifying supply code on disk.

The malware particularly targets the Keypair class from the solders library, intercepting essential constructor strategies together with from_seed, from_bytes, and from_base58_string.

When semantic-types is imported, it mechanically executes code that wraps these strategies with malicious performance whereas preserving their unique habits to keep away from detection.

The interception course of operates by means of a wrapper operate that captures the non-public key bytes instantly after keypair technology.

The malware encrypts the stolen key utilizing a hardcoded RSA-2048 public key and spawns a background thread to transmit the encrypted knowledge by way of a Solana memo transaction to the devnet endpoint.

This strategy ensures that the exfiltration happens asynchronously with out disrupting the conventional utility move, making the compromise nearly invisible to builders and automatic monitoring methods.

Have a good time 9 years of ANY.RUN! Unlock the total energy of TI Lookup plan (100/300/600/1,000+ search requests), and your request quota will double.

Cyber Security News Tags:Attack, Chain, Keys, Package, Private, PyPI, Solana, Steals, Supply, Weaponized

Post navigation

Previous Post: How to Use Encrypted Messaging Apps
Next Post: Hackers Drop Info-Stealing Malware On TikTok Users Device Using AI-Generated Videos

Related Posts

Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Qilin Ransomware Leverages TPwSav.sys Driver to Disable EDR Security Measures Cyber Security News
93+ Billion Stolen Users’ Cookies Flooded by Hackers on the Dark Web 93+ Billion Stolen Users’ Cookies Flooded by Hackers on the Dark Web Cyber Security News
New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users Cyber Security News
Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash Cyber Security News
Exim Vulnerability Enables Remote Code Execution Exim Vulnerability Enables Remote Code Execution Cyber Security News
Microsoft Defender Identifies New Trojanized Gaming Tool Threat Microsoft Defender Identifies New Trojanized Gaming Tool Threat Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark