Researchers uncovered a coordinated npm supply-chain campaign in which five packages published from the galedonovan account impersonated trusted Solana and Ethereum libraries to steal private wallet keys. The packages used function hooking to intercept sensitive material during normal key-handling operations, including Solana Base58 decode() flows and the Ethereum wallet constructor, then exfiltrated the keys in plaintext to a hardcoded Telegram bot, @Test20131_Bot, and a group administered by @crypto_sol3.
The campaign affected both direct installs and transitive dependencies, with bs58-basic pulling in the malicious base-x-64, while ethersproject-wallet closely mimicked the legitimate @ethersproject/wallet 5.8.0 release with only a small injected change. One package, base_xd, was removed within minutes, but researchers said it shared the same payload and infrastructure as base-x-64; four packages were still live when the activity was disclosed. Developers who installed the packages were urged to remove them immediately, treat any exposed private keys as compromised, rotate keys, and move funds to new wallets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Socket publicly reported the malicious npm supply-chain campaign, linked the five packages to the same exfiltration infrastructure, and submitted takedown requests. It advised affected developers to remove the packages immediately, rotate any exposed private keys, and move funds from potentially compromised wallets.
The package base_xd was removed from npm within five minutes of publication, but researchers found it used the same payload and Telegram-based exfiltration infrastructure as base-x-64. The other four malicious packages remained available at the time of discovery.
Five npm packages published under the account "galedonovan" impersonated Solana and Ethereum libraries and were designed to steal private wallet keys from developers. The campaign included packages such as base-x-64, bs58-basic, and ethersproject-wallet, with some packages also creating transitive compromise paths through dependencies.
Socket's Threat Research Team confirmed that the hardcoded Telegram bot @Test20131_Bot and associated group administered by @crypto_sol3 were active, enabling plaintext exfiltration of stolen private keys. The malware hooked key-handling functions in Solana and Ethereum libraries while preserving normal behavior to avoid detection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.