Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets

A newly discovered supply chain campaign is putting Solana developers at serious risk, with attackers hiding malicious code inside fake developer packages on npm and PyPI. The operation, tracked as “Solana FakeFix,” deployed 25 malicious packages designed to steal wallet keys, cloud credentials, SSH keys, and developer secrets the moment a package is installed or […]

The post Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: