Solana FakeFix is a supply-chain threat cluster that distributed malicious packages through npm and PyPI while impersonating legitimate Solana development tooling. The operation primarily targeted Solana developers, especially users troubleshooting dependency conflicts or build issues, and also included a separate CMS-themed cluster aimed at Windows users. The actor used convincing typosquat and lookalike package naming and promoted the packages through GitHub issue spam to drive installations. The Solana-focused cluster delivered malicious code either during npm installation via postinstall hooks or when Python packages were imported. Payloads searched for Solana wallet material, SSH private keys, cloud credentials, environment files, and sensitive environment variables, then exfiltrated the collected data to attacker-controlled Telegram infrastructure. More advanced variants embedded stealer functionality into otherwise usable Solana-related packages, improving deception while preserving malicious behavior. Observed capabilities included credential theft, crypto theft, exfiltration, persistence, and post-exploitation. Advanced variants established backdoor access by polling Telegram for remote commands, enabling arbitrary shell command execution and additional collection from compromised hosts. One variant attempted to drain Solana funds and alter local RPC settings, while another package masqueraded as an automated MEV profit tool to phish for Solana private keys. A second cluster used CMS-themed npm packages to target Windows systems. These packages executed install-time PowerShell to install Deno, retrieve remote JavaScript or executables, and maintain persistence through Windows autorun mechanisms. Some packages functioned as download-and-execute droppers for Windows payloads and periodically fetched second-stage content. The activity is best characterized as financially motivated software supply-chain abuse focused on theft of cryptocurrency assets, developer secrets, and cloud credentials. No high-confidence attribution to a nation-state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.