Solana A.I CyberSecurity Scoring
Solana
Company Information
Website:https://www.solana.com
Employees number:531
Number of followers:128,691
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:solana.com
Solana Risk Score (AI oriented)
Between 700 and 749
SolanaTechnology, Information and Internet
Updated:
22/08/2026
22/08/2026
726/1000
Moderate
Ba
Solana Global Score (TPRM)
xxxx
SolanaTechnology, Information and Internet
Score locked

SolanaModerate
Current Score
726Ba (MODERATE)
01000
2 incidents
-25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
745
Cyber Attack
21 Aug 2026 • Solana
Solana and Ethereum: Rust’s arrayref Crate Hit by Malware in Supply Chain Breach Hitting 245M Downloads
Rust Ecosystem Supply Chain Attack Targeting Foundational Crates
726
CRITICAL-19
ETHSOL1787410277
Rust Ecosystem Hit by Supply Chain Attack Targeting Foundational Crate
On August 20, 2026, attackers compromised a maintainer account in the Rust programming ecosystem, pushing malware-laced versions of the widely used arrayref crate and two others internment and append-only-vec. The attack exploited Rust’s build system, executing malicious code automatically during compilation without requiring explicit function calls from developers. Simply building a project that depended on these crates was enough to trigger the infection.
The compromised crates are deeply embedded in the Rust supply chain, with arrayref alone recording roughly 245 million lifetime downloads. They underpin critical tools in graphics, cryptography, and blockchain development, including components of the Ethereum and Solana software stacks. The attack’s speed and precision were notable: the entire operation, from initial compromise to remediation, unfolded in roughly two hours.
### How the Attack Unfolded
The attackers began by impersonating David Tolnay, a prominent Rust community member, to publish a typosquatted package named proc-macro1 a near-identical mimic of the trusted proc-macro2 crate. Initially, proc-macro1 contained legitimate code, but a subsequent update introduced a hidden build.rs script. When executed during compilation, this script downloaded a payload tailored to the host operating system (Unix or Windows), establishing persistence and targeting saved browser credentials from Chrome, Brave, and Edge.
Within minutes, the attackers also poisoned arrayref (v0.3.10), internment (v0.8.7), and append-only-vec (v0.1.9), all maintained by Andrew Gallant (known as BurntSushi). Investigators believe the attacker gained access to a single compromised account or machine, rather than exploiting vulnerabilities in the code itself.
### Timeline of Compromised Releases
| Crate | Malicious Version | Published (UTC) | Removed (UTC) | Exposure Window |
|---------------------|-------------------|-----------------|---------------|-----------------|
| arrayref | 0.3.10 | 07:15 | 08:41 | 86 minutes |
| internment | 0.8.7 | Not specified | Not specified | ~90 minutes |
| append-only-vec | 0.1.9 | 07:37 | 09:25 | 107 minutes |
### Response and Attribution
The Rust Security Response Team acted swiftly, removing the malicious packages from crates.io and restoring yanked versions of arrayref to prevent further exposure. The team confirmed the maintainer was not complicit, attributing the breach to a compromised account or machine. Nextron Systems’ research team was credited with discovering the attack.
Security firm Wiz identified infrastructure overlaps with previous supply chain campaigns linked to North Korean state-backed groups, including the Mastra and Axios operations. While not a definitive attribution, the pattern aligns with a broader trend of state-sponsored actors targeting open-source registries to infiltrate developer environments.
### Why the Attack Succeeded
The incident highlighted two key vulnerabilities:
1. Automated Build Execution: Rust’s build.rs mechanism allows arbitrary code to run during compilation, a feature exploited to deliver malware without altering the crate’s visible source code.
2. Manipulation of Cargo’s Safety Features: By yanking older, clean versions of arrayref, the attacker leveraged Cargo’s warning system to steer developers toward the compromised release.
### Impact and Broader Implications
The attack underscores the risks of supply chain compromises in mature ecosystems, where a single maintainer account can expose thousands of downstream projects. While the Rust Project’s rapid response limited the damage, the incident serves as a reminder of the persistent threat posed by credential theft and typosquatting in open-source registries. Organizations relying on Rust for critical infrastructure particularly in blockchain and cryptography are advised to monitor official advisories as further details emerge.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
744
JUNE 2026
744
MAY 2026
743
APRIL 2026
693
MARCH 2026
773
Cyber Attack
19 Mar 2026 • Solana
Solana and Windurf IDE: Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data
Malicious VS Code Extension Targets Developers via Solana Blockchain
742
HIGH-31
WINSOL1773923036
Malicious VS Code Extension Targets Developers via Solana Blockchain
Cybersecurity researchers at Bitdefender have uncovered a sophisticated attack targeting developers through a malicious extension for the Windurf IDE, a popular coding environment. The threat disguises itself as a legitimate tool for the R programming language, using the filename reditorsupporter.r-vscode-2.8.8-universal a near-identical mimic of the trusted REditorSupport extension.
Once installed, the malware leverages an unconventional command-and-control (C2) method: the Solana blockchain. Instead of relying on traditional servers, it retrieves encrypted JavaScript payloads from transactions on the Solana network, making detection and blocking more difficult. The malware then deploys files like w.node and c_x64.node to execute data theft.
The attack is highly selective, performing system profiling to avoid infecting users in Russia likely to evade local law enforcement. For non-Russian targets, it steals passwords and session cookies from browsers like Google Chrome. To maintain persistence, it creates a hidden PowerShell task (UpdateApp) that reactivates the malware on system startup, ensuring continued access even if the IDE is closed.
The campaign specifically targets developers due to their access to high-value credentials, such as API keys, which could grant attackers deeper access to corporate networks. The discovery highlights the growing risk of supply-chain attacks via trusted development tools.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
773
JANUARY 2026
773
DECEMBER 2025
773
NOVEMBER 2025
773
OCTOBER 2025
773
SEPTEMBER 2025
773
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Solana ??
What was Solana's A.I Rankiteo Cyber Score in July 2026 ??
What was Solana's A.I Rankiteo Cyber Score in June 2026 ??
What was Solana's A.I Rankiteo Cyber Score in May 2026 ??
What was Solana's A.I Rankiteo Cyber Score in April 2026 ??
What was Solana's A.I Rankiteo Cyber Score in March 2026 ??
What was Solana's A.I Rankiteo Cyber Score in February 2026 ??
What was Solana's A.I Rankiteo Cyber Score in January 2026 ??
What was Solana's A.I Rankiteo Cyber Score in December 2025 ??
What was Solana's A.I Rankiteo Cyber Score in November 2025 ??
What was Solana's A.I Rankiteo Cyber Score in October 2025 ??
What was Solana's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Solana's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Solana ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Solana's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?