Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Crypto Stealing Solana Trading Bot on GitHub Exposed

Crypto Stealing Solana Trading Bot on GitHub Exposed

2025/07/05 00:15
By:

A GitHub page pretending to be a real Solana trading bot was found to be hiding malware that steals crypto. The page was created by a user named “zldp2002” and looked like a real open-source tool. But when users ran it, their crypto got stolen.

The problem came to light after someone lost their funds. Blockchain security firm SlowMist looked into it and found the bot used strange coding patterns and had many fake stars and forks on GitHub to look trustworthy. For further context, all the code was uploaded around three weeks ago.

SlowMist found that the trading bot was built using Node.js and included a package named crypto-layout-utils. This package was already removed from the official Node.js (NPM) registry. Instead of using the official source, the attacker had users download it from a different GitHub page. This raised further suspicion.

When SlowMist experts scanned the package, they detected that it was highly obfuscated (made difficult on purpose) via a jsjiami.com webpage. Upon decoding, they discovered that the package scanned users’ local files. If it detected any wallet-related information or private keys, it would silently send the information to a remote server operated by the attacker.

The analysis also indicated that this was not the only malicious project. The hacker probably had multiple GitHub accounts for publishing similar spoofed projects. These projects were copied (forked) from actual ones and slightly modified to contain malware. Some used another malicious package named bs58-encrypt-utils-1.0.3, which was first introduced on June 12.

This case is part of a larger wave of cyberattacks on crypto users. Recently, hackers also targeted Firefox users with fake wallet extensions and used GitHub to spread harmful code.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

What is the overseas crypto community talking about today?

What were foreigners most concerned about in the past 24 hours?

BlockBeats2025/12/12 21:23
What is the overseas crypto community talking about today?

The Dark Side of Altcoins

Why is it said that almost all altcoins will go to zero, with only a few exceptions?

ForesightNews 速递2025/12/12 21:03
The Dark Side of Altcoins

On the night of the Federal Reserve rate cut, the real game is Trump’s “monetary power grab”

The article discusses the upcoming Federal Reserve interest rate cut decision and its impact on the market, with a focus on the Fed’s potential relaunch of liquidity injection programs. It also analyzes the Trump administration’s restructuring of the Federal Reserve’s powers and how these changes affect the crypto market, ETF capital flows, and institutional investor behavior. Summary generated by Mars AI. This summary was produced by the Mars AI model, and the accuracy and completeness of the generated content are still being iteratively updated.

MarsBit2025/12/12 19:21
On the night of the Federal Reserve rate cut, the real game is Trump’s “monetary power grab”

When the Federal Reserve is politically hijacked, is the next bitcoin bull market coming?

The Federal Reserve announced a 25 basis point rate cut and the purchase of $40 billion in Treasury securities, resulting in an unusual market reaction as long-term Treasury yields rose. Investors are concerned about the loss of the Federal Reserve's independence, believing the rate cut is a result of political intervention. This situation has triggered doubts about the credit foundation of the US dollar, and crypto assets such as bitcoin and ethereum are being viewed as tools to hedge against sovereign credit risk. Summary generated by Mars AI. The accuracy and completeness of this summary are still in the process of iterative updates.

MarsBit2025/12/12 19:21
When the Federal Reserve is politically hijacked, is the next bitcoin bull market coming?
© 2025 Bitget