恶意 NPM 包窃私钥,Solana 用户资产遭盗

深潮Published on 2025-07-04Last updated on 2025-07-04

恶意开源项目植入后门NPM包,窃取用户私钥致Solana钱包资产被盗。

作者:Thinking

编辑:Liz

背景概述

2025 年 7 月 2 日,一名受害者联系到慢雾安全团队,寻求协助分析其钱包资产被盗的原因。事件起因于他前一天使用了一个托管在 GitHub 上的开源项目 —— zldp2002/solana-pumpfun-bot,随后加密资产被盗。

分析过程

我们随即着手调查此次事件。首先访问该项目的 GitHub 仓库:https://github.com/zldp2002/solana-pumpfun-bot,可以看到它的 Star 和 Fork 数量相对较高,但其各个目录下的代码提交时间均集中在三周前,呈现出明显的异常,缺乏正常项目应有的持续更新轨迹。

恶意NPM包窃私钥,Solana用户资产遭盗

这是一个基于 Node.js 的项目。我们首先对其依赖包进行了分析,发现其引用了一个名为 crypto-layout-utils 的第三方包。

恶意NPM包窃私钥,Solana用户资产遭盗

进一步核查发现,该依赖包已被 NPM 官方下架,而且 package.json 中指定的版本并未出现在 NPM 官方的历史记录中。我们初步判断该包为可疑组件,并已无法通过 NPM 官方源进行下载。那么,受害者又是如何获取到这个恶意依赖的呢?

恶意NPM包窃私钥,Solana用户资产遭盗

继续深入项目,我们在 package-lock.json 文件中找到了关键线索:攻击者将 crypto-layout-utils 的下载链接替换成了:https://github.com/sjaduwhv/testing-dev-log/releases/download/1.3.1/crypto-layout-utils-1.3.1.tgz。

恶意NPM包窃私钥,Solana用户资产遭盗

我们下载了这个可疑的依赖包:crypto-layout-utils-1.3.1,发现这是一个使用 jsjiami.com.v7 进行高度混淆后的代码,这增加了分析的难度。

恶意NPM包窃私钥,Solana用户资产遭盗

恶意NPM包窃私钥,Solana用户资产遭盗

解混淆后我们确认了这是一个恶意的 NPM 包,攻击者在 crypto-layout-utils-1.3.1 中实现了扫描受害者电脑文件的逻辑,如果发现钱包或私钥相关的内容或文件就上传到攻击者控制的服务器上(githubshadow.xyz)。

恶意 NPM 包扫描敏感文件和目录:

恶意NPM包窃私钥,Solana用户资产遭盗

恶意 NPM 包上传包含私钥的内容或文件:

恶意NPM包窃私钥,Solana用户资产遭盗

我们继续探索攻击手法,项目作者(https://github.com/zldp2002/) 疑似控制了一批 GitHub 账号, 用于 Fork 恶意项目并进行恶意程序分发,同时刷高项目的 Fork 和 Star 数量,引诱更多用户关注,以便扩大恶意程序的分发范围。

恶意NPM包窃私钥,Solana用户资产遭盗

我们还识别出多个 Fork 项目也存在类似恶意行为,其中部分版本使用了另一款恶意包 bs58-encrypt-utils-1.0.3。

该恶意包自 2025 年 6 月 12 日创建,猜测攻击者这时候就已经开始分发恶意 NPM 和恶意 Node.js 项目,但在 NPM 下架 bs58-encrypt-utils 后,攻击者改用了替换 NPM 包下载链接的方式进行分发。

恶意NPM包窃私钥,Solana用户资产遭盗

此外,我们使用链上反洗钱与追踪工具 MistTrack 分析发现,其中一个攻击者地址盗币后,将资金转移至了交易平台 FixedFloat。

恶意NPM包窃私钥,Solana用户资产遭盗

总结

本次攻击事件中,攻击者通过伪装为合法开源项目(solana-pumpfun-bot),诱导用户下载并运行恶意代码。在刷高项目热度的掩护下,用户在毫无防备的情况下运行了携带恶意依赖的 Node.js 项目,导致钱包私钥泄露、资产被盗。

整个攻击链条涉及多个 GitHub 账号协同操作,扩大了传播范围,提升了可信度,极具欺骗性。同时,这类攻击通过社会工程与技术手段双管齐下,在组织内部也很难完全防御。

我们建议开发者与用户高度警惕来路不明的 GitHub 项目,尤其是在涉及钱包或私钥操作时。如果确实需要运行调试,建议在独立且没有敏感数据的机器环境运行和调试。

 

恶意依赖包相关信息

恶意 Node.js 项目的 GitHub 仓库:

2723799947qq2022/solana-pumpfun-bot

2kwkkk/solana-pumpfun-bot

790659193qqch/solana-pumpfun-bot

7arlystar/solana-pumpfun-bot

918715c83/solana-pumpfun-bot

AmirhBeigi7zch6f/solana-pumpfun-bot

asmaamohamed0264/solana-pumpfun-bot

bog-us/solana-pumpfun-bot

edparker89/solana-pumpfun-bot

ii4272/solana-pumpfun-bot

ijtye/solana-pumpfun-bot

iwanjunaids/solana-pumpfun-bot

janmalece/solana-pumpfun-bot

kay2x4/solana-pumpfun-bot

lan666as2dfur/solana-pumpfun-bot

loveccat/solana-pumpfun-bot

lukgria/solana-pumpfun-bot

mdemetrial26rvk9w/solana-pumpfun-bot

oumengwas/solana-pumpfun-bot

pangxingwaxg/solana-pumpfun-bot

Rain-Rave5/solana-pumpfun-bot

wc64561673347375/solana-pumpfun-bot

wj6942/solana-pumpfun-bot

xnaotutu77765/solana-pumpfun-bot

yvagSirKt/solana-pumpfun-bot

VictorVelea/solana-copy-bot

Morning-Star213/Solana-pumpfun-bot

warp-zara/solana-trading-bot

harshith-eth/quant-bot

恶意 NPM 包:

crypto-layout-utils

bs58-encrypt-utils

恶意 NPM 包下载链接:

https://github.com/sjaduwhv/testing-dev-log/releases/download/1.3.1/crypto-layout-utils-1.3.1.tgz

恶意 NPM 包上传数据的服务器:

githubshadow.xyz

Trending Cryptos

Related Reads

Hacker Leaks GTA6 and Launches a Token: Leaked Videos Become Ad Space for $CYBERLEEK, Must Buy Tokens to Vote for Next Clip

A hacker group called "CyberLeek" has leaked gameplay footage of the highly anticipated video game *GTA 6*, which is slated for release in 2026. Simultaneously, the group launched a meme token, $CYBERLEEK, on Solana. The leaks, which include maps and gameplay clips, are heavily watermarked with advertisements urging viewers to buy the token. Investigations of blockchain data reveal that the token was created and funded from a single wallet approximately eight hours before the first leak was released, suggesting a coordinated plan. The group has implemented a voting system where token holders can "vote" for the next type of content to be leaked by sending $CYBERLEEK tokens to a designated wallet—a process that permanently transfers the tokens to the hackers. This creates a self-sustaining cycle where interest in the leaks drives token purchases. Financially, the operation involved minimal upfront costs (less than $3,500 in out-of-pocket expenses) but generated significant revenue. On its first day, the token saw $15 million in trading volume, netting the creators an estimated $30,000 from transaction fees alone. While the group later burned a large portion of its developer-held tokens (worth over $1 million) to build trust, the fee-generating mechanism remains intact. The game's publisher, Take-Two Interactive, has initiated legal proceedings to identify the hackers. Despite this, the case demonstrates a new model where leaked intellectual property is used as leverage to promote and profit from a cryptocurrency, with meme token markets serving as an additional revenue stream.

marsbit15m ago

Hacker Leaks GTA6 and Launches a Token: Leaked Videos Become Ad Space for $CYBERLEEK, Must Buy Tokens to Vote for Next Clip

marsbit15m ago

Jensen Huang's Daughter: From Chef to an $8 Million Annual Salary

Madison Huang, daughter of NVIDIA founder Jensen Huang, recently made a rare public appearance in Beijing during the 2026 World Robot Conference. As the Senior Director of Product and Technology Marketing for NVIDIA's Physical AI Platform, with an annual salary of approximately $1.2 million, her visit focused on evaluating leading Chinese robotics companies like UBTech, Unitree, and others. This highlights NVIDIA's strategic interest in the burgeoning Chinese robotics ecosystem, a key battleground for the development of Physical AI—technology that enables machines to understand and interact with the physical world. Huang's career path is unconventional. Initially pursuing her passion, she studied culinary arts, worked as a chef, and later held a marketing role at LVMH. She joined NVIDIA as an intern in 2020 after completing an MBA, quickly rising through the ranks. Her brother, Spencer Huang, followed a similar path, closing a cocktail bar he co-founded to also join NVIDIA, where he now works on robotics software. Jensen Huang has publicly addressed nepotism concerns, humorously noting that some "second-generation" employees outperform their parents. The conference itself underscored China's vibrant robotics sector, marked by Unitree's recent blockbuster IPO and a pipeline of companies preparing to go public. While hardware development and manufacturing are advancing rapidly, industry leaders like Wang Xingxing of Unitree point to the next critical challenge: developing the "brain" or AI that allows robots to perform diverse, unseen tasks based on simple instructions. With massive manufacturing scale and diverse real-world testing scenarios, China is positioned as a central player in the global race to define the future of robotics.

marsbit2h ago

Jensen Huang's Daughter: From Chef to an $8 Million Annual Salary

marsbit2h ago

He Gave Wang Xingxing the First 2 Million, Now Serves as Chairman for the Next 'Unitree'

On August 19, 2024, Unitree Robotics, China's "first humanoid robotics stock," went public. Its founder, Wang Xingxing, started a decade ago with his self-developed XDog. In 2016, at a critical funding juncture, he received his first angel investment of 2 million RMB from Yin Fangming. This bet has since yielded a return of over 140 times. Yin Fangming is more than just a key investor. He was a co-founder of the AI robotics company ROOBO, whose own venture ultimately struggled. This firsthand experience with the hardware challenges in robotics gave him unique insight when backing Unitree, a company renowned for its hardware R&D and cost control. While his own company faltered, Yin continued investing shrewdly. He partially cashed out some Unitree shares early, reinvesting the proceeds into sectors like energy (e.g., solid-state battery firm TaiLan) and commercial aerospace (e.g., small launch vehicle developer XianDeng Aerospace). However, his most significant move after Unitree is his deep involvement with Galaxy General, a leading embodied AI unicorn. In July 2024, Yin stepped from behind the scenes to officially become its Chairman, indicating a role far beyond a typical investor. This comes as Galaxy General is viewed as preparing for future capital moves. Yin's career has consistently been ahead of the curve—from mobile internet to AI and robotics. Known for his foresight and low profile, he declined an interview for this story, offering only a statement encouraging support for visionary entrepreneurs like Wang Xingxing.

marsbit3h ago

He Gave Wang Xingxing the First 2 Million, Now Serves as Chairman for the Next 'Unitree'

marsbit3h ago

Coldcard Theft Reflection: Source Code Visibility Does Not Equal Security

The article examines the open-source vs. closed-source debate in crypto, prompted by a theft of over $100M in Bitcoin from Coldcard hardware wallets. It clarifies key terminology: true "Free and Open Source Software" (FOSS) grants four essential freedoms (use, study, share, modify), while "source available" code, like Coldcard's firmware, may have usage restrictions. The piece argues that visible source code alone does not guarantee security; actual safety depends on the economic incentives for thorough, ongoing review by skilled individuals. Using Bitcoin Core as a model, the article describes a successful, transparent open-source development culture built on public review and consensus. It contrasts this with the Coldcard case, where a critical bug in a lightly-reviewed, source-available library went undetected for years, highlighting a "tragedy of the commons" scenario where assumed but absent scrutiny creates vulnerability. The economics of licensing are crucial: restrictive licenses can limit the pool of motivated commercial reviewers. Finally, the article explores AI's impact. It cites the Bitcoin Red Team's use of AI to rapidly audit codebases and find vulnerabilities at scale, demonstrating a powerful new tool for security. However, AI also floods projects with low-quality code, straining maintainers. The piece concludes that in high-stakes crypto, only well-audited projects—whether open or closed-source—can withstand evolving threats, with AI both challenging and aiding security practices.

marsbit3h ago

Coldcard Theft Reflection: Source Code Visibility Does Not Equal Security

marsbit3h ago

Trading

Spot

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of SOL (SOL) are presented below.

活动图片