Incident tracker · 3 Dec 2024

Are you exposed to the @solana/web3.js supply-chain (December 2024)?

Compromised maintainer token led to two malicious releases that exfiltrate Solana private keys at runtime.

Confirmed-compromised packages1 package
npm
@solana/web3.jscompromised: 1.95.6, 1.95.7
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo