A Popular Solana Bot on GitHub Was a Wallet Thief: Supply Chain Attack Analysis
A malicious GitHub project disguised as a Solana trading bot lured developers with inflated Star and Fork counts, then exfiltrated wallet private keys by hijacking an npm dependency's download URL in package-lock.json. Full attack chain from discovery to deobfuscation and C2 exfiltration, spanning 29 malicious repos and 2 rogue npm packages.