Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Crypto Stealing Solana Trading Bot on GitHub Exposed

Crypto Stealing Solana Trading Bot on GitHub Exposed

2025/07/05 00:15
By:
SOL+1.99%

A GitHub page pretending to be a real Solana trading bot was found to be hiding malware that steals crypto. The page was created by a user named “zldp2002” and looked like a real open-source tool. But when users ran it, their crypto got stolen.

The problem came to light after someone lost their funds. Blockchain security firm SlowMist looked into it and found the bot used strange coding patterns and had many fake stars and forks on GitHub to look trustworthy. For further context, all the code was uploaded around three weeks ago.

SlowMist found that the trading bot was built using Node.js and included a package named crypto-layout-utils. This package was already removed from the official Node.js (NPM) registry. Instead of using the official source, the attacker had users download it from a different GitHub page. This raised further suspicion.

When SlowMist experts scanned the package, they detected that it was highly obfuscated (made difficult on purpose) via a jsjiami.com webpage. Upon decoding, they discovered that the package scanned users’ local files. If it detected any wallet-related information or private keys, it would silently send the information to a remote server operated by the attacker.

The analysis also indicated that this was not the only malicious project. The hacker probably had multiple GitHub accounts for publishing similar spoofed projects. These projects were copied (forked) from actual ones and slightly modified to contain malware. Some used another malicious package named bs58-encrypt-utils-1.0.3, which was first introduced on June 12.

This case is part of a larger wave of cyberattacks on crypto users. Recently, hackers also targeted Firefox users with fake wallet extensions and used GitHub to spread harmful code.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

CZ Discusses the Memecoin Craze, Hyperliquid, and Offers Advice to Entrepreneurs

CZ's life after stepping down, reflections, and deep insights into the future of crypto.

Chaincatcher2025/11/05 11:44

Trending news

More
1
CZ Discusses the Memecoin Craze, Hyperliquid, and Offers Advice to Entrepreneurs
2
Privacy coins surge against the trend—is this a fleeting moment or the dawn of a new era?

Crypto prices

More
Bitcoin
Bitcoin
BTC
$102,381.31
-1.76%
Ethereum
Ethereum
ETH
$3,336.63
-4.93%
Tether USDt
Tether USDt
USDT
$0.9999
+0.02%
XRP
XRP
XRP
$2.24
-1.44%
BNB
BNB
BNB
$947.79
-0.41%
Solana
Solana
SOL
$157.78
-2.23%
USDC
USDC
USDC
$1
+0.02%
TRON
TRON
TRX
$0.2866
+1.95%
Dogecoin
Dogecoin
DOGE
$0.1638
-0.94%
Cardano
Cardano
ADA
$0.5365
-1.10%
How to buy BTC
Bitget lists BTC – Buy or sell BTC quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter