GHSA-jcxm-7wvp-g6p5
HIGHCVE-2024-54134Earlier today, a publish-access account was compromised for @solana/web3.js, a JavaScript library that is commonly used by Solana dapps. This allowed an attacker to publish unauthorized and malicious packages that were modified, allowing them to steal private key material and drain funds from dapps, like bots, that handle private keys directly. This issue should not affect non-custodial wallets, a
- Affected
- >= 1.95.6, < 1.95.8
- Fixed in
- 1.95.8
- Weakness
- CWE-200
- Published
- 2024-12-04
- Source
- github