• bitcoinBitcoin(BTC)$116,704.00-2.09%
  • ethereumEthereum(ETH)$3,650.54-2.34%
  • rippleXRP(XRP)$3.08-5.09%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$775.89-0.67%
  • solanaSolana(SOL)$182.36-3.61%
  • usd-coinUSDC(USDC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.227248-5.41%
  • staked-etherLido Staked Ether(STETH)$3,645.45-2.24%
  • tronTRON(TRX)$0.3160000.14%
  • cardanoCardano(ADA)$0.79-3.31%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$116,597.00-2.05%
  • HyperliquidHyperliquid(HYPE)$42.87-0.21%
  • Wrapped stETHWrapped stETH(WSTETH)$4,408.95-2.47%
  • suiSui(SUI)$3.82-0.55%
  • stellarStellar(XLM)$0.416859-3.99%
  • wrapped-beacon-ethWrapped Beacon ETH(WBETH)$3,923.89-2.46%
  • bitcoin-cashBitcoin Cash(BCH)$538.463.97%
  • hedera-hashgraphHedera(HBAR)$0.2516853.13%
  • Wrapped eETHWrapped eETH(WEETH)$3,909.25-2.38%
  • avalanche-2Avalanche(AVAX)$23.41-3.29%
  • litecoinLitecoin(LTC)$111.24-2.07%
  • leo-tokenLEO Token(LEO)$8.970.01%
  • WETHWETH(WETH)$3,650.89-2.34%
  • shiba-inuShiba Inu(SHIB)$0.000014-1.89%
  • the-open-networkToncoin(TON)$3.14-1.20%
  • USDSUSDS(USDS)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.15%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.34%
  • whitebitWhiteBIT Coin(WBT)$43.63-2.03%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$116,736.00-2.02%
  • uniswapUniswap(UNI)$10.12-3.21%
  • polkadotPolkadot(DOT)$3.99-2.55%
  • moneroMonero(XMR)$323.970.42%
  • bitget-tokenBitget Token(BGB)$4.51-2.82%
  • pepePepe(PEPE)$0.000012-5.29%
  • aaveAave(AAVE)$289.69-1.08%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.190.00%
  • crypto-com-chainCronos(CRO)$0.1283041.08%
  • BittensorBittensor(TAO)$414.22-4.33%
  • daiDai(DAI)$1.000.00%
  • EthenaEthena(ENA)$0.549.66%
  • Pi NetworkPi Network(PI)$0.439817-0.91%
  • nearNEAR Protocol(NEAR)$2.73-1.97%
  • ethereum-classicEthereum Classic(ETC)$22.06-3.45%
  • OndoOndo(ONDO)$1.01-4.78%
  • aptosAptos(APT)$4.65-1.60%
  • internet-computerInternet Computer(ICP)$5.46-2.58%
  • Jito Staked SOLJito Staked SOL(JITOSOL)$222.12-3.35%
  • okbOKB(OKB)$47.82-1.58%
  • bonkBonk(BONK)$0.000033-1.83%
  • kaspaKaspa(KAS)$0.097351-3.39%
  • mantleMantle(MNT)$0.75-0.16%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Pudgy PenguinsPudgy Penguins(PENGU)$0.037334-4.67%
  • algorandAlgorand(ALGO)$0.259509-3.45%
  • Binance-Peg WETHBinance-Peg WETH(WETH)$3,646.59-2.73%
  • USD1USD1(USD1)$1.000.11%
  • arbitrumArbitrum(ARB)$0.428661-2.80%
  • vechainVeChain(VET)$0.025001-1.55%
  • cosmosCosmos Hub(ATOM)$4.59-2.89%
  • gatechain-tokenGate(GT)$17.53-0.46%
  • render-tokenRender(RENDER)$4.04-3.22%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.227672-2.90%
  • worldcoin-wldWorldcoin(WLD)$1.12-4.49%
  • Official TrumpOfficial Trump(TRUMP)$9.86-2.45%
  • fasttokenFasttoken(FTN)$4.510.30%
  • SkySky(SKY)$0.0899674.51%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.72-2.87%
  • sei-networkSei(SEI)$0.320369-2.60%
  • Binance Staked SOLBinance Staked SOL(BNSOL)$194.15-3.60%
  • filecoinFilecoin(FIL)$2.58-2.12%
  • quant-networkQuant(QNT)$119.06-2.77%
  • rocket-pool-ethRocket Pool ETH(RETH)$4,159.28-2.35%
  • sUSDSsUSDS(SUSDS)$1.060.01%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$116,604.00-1.89%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$3,827.02-2.26%
  • SPX6900SPX6900(SPX)$1.73-9.15%
  • JupiterJupiter(JUP)$0.53-3.65%
  • Jupiter Perpetuals Liquidity Provider TokenJupiter Perpetuals Liquidity Provider Token(JLP)$5.04-1.39%
  • StoryStory(IP)$5.270.14%
  • flare-networksFlare(FLR)$0.022165-9.46%
  • kucoin-sharesKuCoin(KCS)$12.01-1.06%
  • USDtbUSDtb(USDTB)$1.00-0.02%
  • xdce-crowd-saleXDC Network(XDC)$0.0859550.04%
  • StakeWise Staked ETHStakeWise Staked ETH(OSETH)$3,840.73-2.13%
  • USDT0USDT0(USDT0)$1.000.12%
  • first-digital-usdFirst Digital USD(FDUSD)$1.00-0.15%
  • Mantle Staked EtherMantle Staked Ether(METH)$3,904.85-2.15%
  • curve-dao-tokenCurve DAO(CRV)$0.98-0.98%
  • CelestiaCelestia(TIA)$1.85-2.05%
  • nexoNEXO(NEXO)$1.330.63%
  • Liquid Staked ETHLiquid Staked ETH(LSETH)$3,944.88-2.18%
  • injective-protocolInjective(INJ)$13.36-3.62%
  • FartcoinFartcoin(FARTCOIN)$1.27-9.57%
  • Polygon Bridged USDT (Polygon)Polygon Bridged USDT (Polygon)(USDT)$1.00-0.01%
  • blockstackStacks(STX)$0.78-2.79%
  • Renzo Restaked ETHRenzo Restaked ETH(EZETH)$3,844.14-2.14%
  • optimismOptimism(OP)$0.69-2.92%
  • bitcoinBitcoin(BTC)$116,704.00-2.09%
  • ethereumEthereum(ETH)$3,650.54-2.34%
  • rippleXRP(XRP)$3.08-5.09%
  • tetherTether(USDT)$1.00-0.03%
  • binancecoinBNB(BNB)$775.89-0.67%
  • solanaSolana(SOL)$182.36-3.61%
  • usd-coinUSDC(USDC)$1.000.00%
  • dogecoinDogecoin(DOGE)$0.227248-5.41%
  • staked-etherLido Staked Ether(STETH)$3,645.45-2.24%
  • tronTRON(TRX)$0.3160000.14%
  • cardanoCardano(ADA)$0.79-3.31%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$116,597.00-2.05%
  • HyperliquidHyperliquid(HYPE)$42.87-0.21%
  • Wrapped stETHWrapped stETH(WSTETH)$4,408.95-2.47%
  • suiSui(SUI)$3.82-0.55%
  • stellarStellar(XLM)$0.416859-3.99%
  • wrapped-beacon-ethWrapped Beacon ETH(WBETH)$3,923.89-2.46%
  • bitcoin-cashBitcoin Cash(BCH)$538.463.97%
  • hedera-hashgraphHedera(HBAR)$0.2516853.13%
  • Wrapped eETHWrapped eETH(WEETH)$3,909.25-2.38%
  • avalanche-2Avalanche(AVAX)$23.41-3.29%
  • litecoinLitecoin(LTC)$111.24-2.07%
  • leo-tokenLEO Token(LEO)$8.970.01%
  • WETHWETH(WETH)$3,650.89-2.34%
  • shiba-inuShiba Inu(SHIB)$0.000014-1.89%
  • the-open-networkToncoin(TON)$3.14-1.20%
  • USDSUSDS(USDS)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.15%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.34%
  • whitebitWhiteBIT Coin(WBT)$43.63-2.03%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$116,736.00-2.02%
  • uniswapUniswap(UNI)$10.12-3.21%
  • polkadotPolkadot(DOT)$3.99-2.55%
  • moneroMonero(XMR)$323.970.42%
  • bitget-tokenBitget Token(BGB)$4.51-2.82%
  • pepePepe(PEPE)$0.000012-5.29%
  • aaveAave(AAVE)$289.69-1.08%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.190.00%
  • crypto-com-chainCronos(CRO)$0.1283041.08%
  • BittensorBittensor(TAO)$414.22-4.33%
  • daiDai(DAI)$1.000.00%
  • EthenaEthena(ENA)$0.549.66%
  • Pi NetworkPi Network(PI)$0.439817-0.91%
  • nearNEAR Protocol(NEAR)$2.73-1.97%
  • ethereum-classicEthereum Classic(ETC)$22.06-3.45%
  • OndoOndo(ONDO)$1.01-4.78%
  • aptosAptos(APT)$4.65-1.60%
  • internet-computerInternet Computer(ICP)$5.46-2.58%
  • Jito Staked SOLJito Staked SOL(JITOSOL)$222.12-3.35%
  • okbOKB(OKB)$47.82-1.58%
  • bonkBonk(BONK)$0.000033-1.83%
  • kaspaKaspa(KAS)$0.097351-3.39%
  • mantleMantle(MNT)$0.75-0.16%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Pudgy PenguinsPudgy Penguins(PENGU)$0.037334-4.67%
  • algorandAlgorand(ALGO)$0.259509-3.45%
  • Binance-Peg WETHBinance-Peg WETH(WETH)$3,646.59-2.73%
  • USD1USD1(USD1)$1.000.11%
  • arbitrumArbitrum(ARB)$0.428661-2.80%
  • vechainVeChain(VET)$0.025001-1.55%
  • cosmosCosmos Hub(ATOM)$4.59-2.89%
  • gatechain-tokenGate(GT)$17.53-0.46%
  • render-tokenRender(RENDER)$4.04-3.22%
  • polygon-ecosystem-tokenPOL (ex-MATIC)(POL)$0.227672-2.90%
  • worldcoin-wldWorldcoin(WLD)$1.12-4.49%
  • Official TrumpOfficial Trump(TRUMP)$9.86-2.45%
  • fasttokenFasttoken(FTN)$4.510.30%
  • SkySky(SKY)$0.0899674.51%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.72-2.87%
  • sei-networkSei(SEI)$0.320369-2.60%
  • Binance Staked SOLBinance Staked SOL(BNSOL)$194.15-3.60%
  • filecoinFilecoin(FIL)$2.58-2.12%
  • quant-networkQuant(QNT)$119.06-2.77%
  • rocket-pool-ethRocket Pool ETH(RETH)$4,159.28-2.35%
  • sUSDSsUSDS(SUSDS)$1.060.01%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$116,604.00-1.89%
  • Kelp DAO Restaked ETHKelp DAO Restaked ETH(RSETH)$3,827.02-2.26%
  • SPX6900SPX6900(SPX)$1.73-9.15%
  • JupiterJupiter(JUP)$0.53-3.65%
  • Jupiter Perpetuals Liquidity Provider TokenJupiter Perpetuals Liquidity Provider Token(JLP)$5.04-1.39%
  • StoryStory(IP)$5.270.14%
  • flare-networksFlare(FLR)$0.022165-9.46%
  • kucoin-sharesKuCoin(KCS)$12.01-1.06%
  • USDtbUSDtb(USDTB)$1.00-0.02%
  • xdce-crowd-saleXDC Network(XDC)$0.0859550.04%
  • StakeWise Staked ETHStakeWise Staked ETH(OSETH)$3,840.73-2.13%
  • USDT0USDT0(USDT0)$1.000.12%
  • first-digital-usdFirst Digital USD(FDUSD)$1.00-0.15%
  • Mantle Staked EtherMantle Staked Ether(METH)$3,904.85-2.15%
  • curve-dao-tokenCurve DAO(CRV)$0.98-0.98%
  • CelestiaCelestia(TIA)$1.85-2.05%
  • nexoNEXO(NEXO)$1.330.63%
  • Liquid Staked ETHLiquid Staked ETH(LSETH)$3,944.88-2.18%
  • injective-protocolInjective(INJ)$13.36-3.62%
  • FartcoinFartcoin(FARTCOIN)$1.27-9.57%
  • Polygon Bridged USDT (Polygon)Polygon Bridged USDT (Polygon)(USDT)$1.00-0.01%
  • blockstackStacks(STX)$0.78-2.79%
  • Renzo Restaked ETHRenzo Restaked ETH(EZETH)$3,844.14-2.14%
  • optimismOptimism(OP)$0.69-2.92%

A newly uncovered scam involving a fake Solana trading bot on GitHub has resulted in stolen cryptocurrency funds, according to a report by blockchain security firm SlowMist. The fraudulent repository, named solana-pumpfun-bot and hosted by the GitHub account “zldp2002,” disguised itself as a legitimate open-source Solana trading tool while secretly delivering malware.

The scam came to light after a user reported their crypto funds had vanished shortly after interacting with the code. This triggered SlowMist’s investigation, which revealed that the repository had a “relatively high number of stars and forks.”

Obscured Malware Hidden in Node.js Package

The malicious bot was built using Node.js and included a suspicious third-party dependency called crypto-layout-utils. Investigators discovered that this package had already been removed from the official NPM (Node Package Manager) registry, raising immediate red flags. However, instead of retrieving it through legitimate channels, the malware downloaded the package from a separate GitHub repository under the attacker’s control.

SlowMist analysts noted that the package was heavily obfuscated using jsjiami.com.v7, a tool designed to make JavaScript code harder to read and analyse. Once decrypted, the researchers found that the malware scanned local files for sensitive wallet data and private keys. Any discovered credentials were uploaded to a remote server, resulting in the theft of crypto assets.

A Larger Network of Malicious Repositories

Further analysis by SlowMist suggests that the incident was not isolated. The attacker appears to control a network of GitHub accounts, used to fork popular projects and inject malicious code into them. These cloned repositories also showed unusually high star and fork counts, artificially boosted to lure unsuspecting users.

A screenshot of the now-deleted GitHub repository. Source: SlowMist
A screenshot of the now-deleted GitHub repository. Source: SlowMist

Some versions of the repositories included another malware-laden package called bs58-encrypt-utils-1.0.3, created on 12 June 2025. This date marks what researchers believe to be the beginning of a coordinated campaign distributing tainted NPM modules and Node.js-based malware through GitHub.

SlowMist’s report indicates that these repositories followed similar structural patterns, often lacking the consistency expected of genuine open-source projects. The lack of standard development practices, including proper versioning and commit messages, helped confirm the repositories’ fraudulent nature.

Supply Chain Attacks on the Rise in Crypto Space

This incident is part of a growing wave of software supply chain attacks aimed at the crypto community. Attackers are increasingly exploiting platforms like GitHub and browser extensions to insert credential-stealing code into seemingly legitimate tools and applications.

In recent weeks, fake wallet extensions for browsers such as Firefox have surfaced, similarly designed to trick users into compromising their wallets. These scams are becoming more sophisticated, often using real branding, cloned project histories, and inflated reputation metrics to appear trustworthy.

Staying Safe: What Users Should Do

Crypto users are urged to exercise extreme caution when downloading software from public repositories. Always verify the source, check for inconsistencies in commit history, avoid unverified packages, and run code in isolated environments before using with any real wallet data.

The SlowMist team recommends monitoring the community and cross-checking any new crypto tools with official documentation or known developers. As the software supply chain continues to be a weak point, vigilance is key to protecting digital assets in an increasingly hostile cyber environment.

Related Posts