Close Menu
Cryprovideos
    What's Hot

    Chainweb EVM di Kadena: the revolution of blockchain for DeFi and RWA

    July 5, 2025

    No Room For Bears: Bitcoin Bullish MACD, Month-to-month Shut Gasoline Bullish Outlook

    July 5, 2025

    20,500: Mega Bitcoin Whale Accumulation Recorded

    July 5, 2025
    Facebook X (Twitter) Instagram
    Cryprovideos
    • Home
    • Crypto News
    • Bitcoin
    • Altcoins
    • Markets
    Cryprovideos
    Home»Altcoins»Solana PumpFun Bot Turns Out to Be Malware in Disguise
    Solana PumpFun Bot Turns Out to Be Malware in Disguise
    Altcoins

    Solana PumpFun Bot Turns Out to Be Malware in Disguise

    By Crypto EditorJuly 5, 2025No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A malicious open-source venture on GitHub disguised as a Solana buying and selling bot has compromised person wallets, in accordance with a July 2, 2025, report by cybersecurity agency SlowMist.

    The venture, referred to as “solana-pumpfun-bot”, was printed underneath the GitHub person zldp2002 and shortly gained traction in the neighborhood. However as a substitute of providing actual performance, the bot silently stole cryptocurrencies from customers’ wallets and funneled the funds to a platform referred to as FixedFloat.

    Pretend Bundle, Actual Injury

    SlowMist’s investigation revealed that the bot was constructed with Node.js and used a shady dependency named “crypto-layout-utils”, which isn’t listed in official NPM repositories. As soon as put in, this bundle silently scanned for personal keys and pockets recordsdata on the person’s machine and despatched them to an attacker-controlled server, githubshadow.xyz.

    The malware’s code was closely obfuscated, making it tough to detect. The attacker additionally forked the venture a number of instances utilizing pretend GitHub accounts, amplifying publicity. A few of these forks used an alternate malicious bundle, “bs58-encrypt-utils-1.0.3”.

    Assault Energetic Since Mid-June

    The assault seems to have been energetic since June 12, 2025, and was solely found after a sufferer contacted SlowMist a day after putting in the venture. Publish-exploit on-chain evaluation utilizing SlowMist’s MistTrack software confirmed the stolen funds have been routed to FixedFloat.

    Skilled Warning

    SlowMist strongly cautioned towards working GitHub-based open-source software program that interacts with wallets or non-public keys until completed in a extremely remoted atmosphere. The agency recommends avoiding suspicious or unverified packages, particularly in crypto bot frameworks and automation instruments.

    The case underscores the rising danger of social engineering and dependency hijacking in open-source crypto growth — and the significance of verifying each part earlier than execution.

    Solana PumpFun Bot Turns Out to Be Malware in Disguise
    Twitter

    Linkedin

    Kosta has been working within the crypto business for over 4 years. He strives to current completely different views on a given subject and enjoys the sector for its transparency and dynamism. In his work, he focuses on balanced protection of occasions and developments within the crypto house, offering data to his readers from a impartial perspective.

    Telegram



    Supply hyperlink

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Taiko and Nethermind Associate to Improve Ethereum Rollup Infrastructure

    July 5, 2025

    XRP Worth Eyes 70% Surge To $3.99 As Amid Trendline Take a look at | Bitcoinist.com

    July 5, 2025

    Solana’s At a Crossroads—Breakout or Breakdown? ‣ BlockNews

    July 5, 2025

    Solana Checks Rising Channel Assist – Breakdown May Ship Worth To $128.50 Stage

    July 5, 2025
    Latest Posts

    No Room For Bears: Bitcoin Bullish MACD, Month-to-month Shut Gasoline Bullish Outlook

    July 5, 2025

    20,500: Mega Bitcoin Whale Accumulation Recorded

    July 5, 2025

    Historic Bitcoin Whales Abruptly Come Alive, Transfer $2,183,000,000+ in BTC After Mendacity Dormant for 14+ Years: On-Chain Information – The Every day Hodl

    July 5, 2025

    You Can Purchase a Martian Meteorite With Bitcoin—If You Have Upwards of $4 Million – Decrypt

    July 5, 2025

    Eight Bitcoin Wallets Transfer 80,000 BTC in Largest Ever ‘Satoshi Period’ Transfers

    July 5, 2025

    Mexican billionaire says promote your property, purchase Bitcoin as fiat nears collapse

    July 5, 2025

    Bitcoin Tops Crypto Social Buzz as $110,000 Milestone Fuels Market Debate

    July 5, 2025

    'Wealthy Dad Poor Dad' Creator: ‘I Hope Bitcoin Crashes. I Will Purchase Extra’

    July 5, 2025

    CryptoVideos.net is your premier destination for all things cryptocurrency. Our platform provides the latest updates in crypto news, expert price analysis, and valuable insights from top crypto influencers to keep you informed and ahead in the fast-paced world of digital assets. Whether you’re an experienced trader, investor, or just starting in the crypto space, our comprehensive collection of videos and articles covers trending topics, market forecasts, blockchain technology, and more. We aim to simplify complex market movements and provide a trustworthy, user-friendly resource for anyone looking to deepen their understanding of the crypto industry. Stay tuned to CryptoVideos.net to make informed decisions and keep up with emerging trends in the world of cryptocurrency.

    Top Insights

    Iran-based crypto change hacked for $48M amid cyberattack claims by Israel-linked group

    June 18, 2025

    The Martin Act Concentrating on the Crypto Business?

    April 21, 2025

    Crypto Merchandise See ‘Noticeable Deceleration’ of Inflows As Financial Coverage Uncertainty Grows: CoinShares – The Day by day Hodl

    June 10, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    • Home
    • Privacy Policy
    • Contact us
    © 2025 CryptoVideos. Designed by MAXBIT.

    Type above and press Enter to search. Press Esc to cancel.