Solana Labs A.I CyberSecurity Scoring
Solana Labs
Company Information
Website:https://solanalabs.com/
Employees number:261
Number of followers:100,100
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:solanalabs.com
Solana Labs Risk Score (AI oriented)
Between 650 and 699
Solana LabsTechnology, Information and Internet
Updated:
03/04/2026
03/04/2026
672/1000
Weak
B
Solana Labs Global Score (TPRM)
xxxx
Solana LabsTechnology, Information and Internet
Score locked

Solana LabsWeak
Current Score
672B (WEAK)
01000
3 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
677
MAY 2026
675
APRIL 2026
674
MARCH 2026
691
Cyber Attack
23 Mar 2026 • Solana Labs
npm, Solana and Ethereum: Five Malicious npm Packages Target Crypto Developers, Steal Wallet Keys via Telegram
Malicious npm Packages Target Solana and Ethereum Developers in Supply Chain Attack
672
CRITICAL-19
NPMSOLETH1774427254
Malicious npm Packages Target Solana and Ethereum Developers in Supply Chain Attack
A recent supply chain attack has compromised cryptocurrency developers by distributing five malicious npm packages that steal wallet private keys and exfiltrate them to a Telegram-based command-and-control (C2) server. The packages, published under the npm account galedonovan, impersonate legitimate crypto libraries to target both Solana and Ethereum ecosystems.
The identified packages raydium-bs58, base-x-64, bs58-basic, ethersproject-wallet, and the briefly published base_xd were designed to intercept private key operations. For Solana developers, the packages hijack Base58 decode() calls, while the Ethereum-focused ethersproject-wallet triggers malicious code within the Wallet constructor. In all cases, stolen keys are sent to a hardcoded Telegram bot (@Test20131_Bot) before legitimate operations complete, allowing attackers to drain compromised wallets.
The attack leverages typosquatting and dependency confusion, with some packages (bs58-basic) containing no malicious code themselves but relying on base-x-64 to execute the theft. Obfuscation techniques, including array-rotation ciphers, were used to conceal the Telegram C2 endpoint, though one package (raydium-bs58) accidentally exposed the bot token and group invite URL in a comment.
The campaign, active as of March 23, 2026, was discovered by Socket, which submitted takedown requests for the packages and the associated npm account. However, four of the five packages remained available in the registry at the time of analysis. The attack infrastructure relies solely on the Telegram bot, meaning exfiltration remains operational as long as the bot is active.
Attribution artifacts such as shared typos in package.json, identical compiled binaries, and uniform file timestamps strongly suggest a single developer behind the campaign. The operator’s Telegram handle (@crypto_sol3) was linked to the bot’s administration group. The malicious packages exploit Node.js 18+ environments, failing silently on older versions due to a missing fetch() API dependency.
Developers are advised to remove the affected packages and treat any exposed keys as compromised, though the summary strictly focuses on the incident’s details.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
690
JANUARY 2026
688
DECEMBER 2025
686
NOVEMBER 2025
686
OCTOBER 2025
684
SEPTEMBER 2025
683
AUGUST 2025
681
JULY 2025
680
JANUARY 2025
726
Breach
01 Jan 2025 • Solana Labs
Solana
Malicious npm and PyPI Packages Targeting Solana's Ecosystem
669
CRITICAL-57
SOL000012425
Malicious npm and PyPI packages were crafted to target Solana's ecosystem, with the intent to steal private keys and drain funds from victims' wallets. The operation involved typosquatting and names mimicking popular libraries, with the theft executed via Gmail SMTP servers to evade detection. Despite discovery and reporting, the malicious packages remained live at that time. Attackers rigged the packages to programmatically transfer the majority of wallet contents to their address, carefully leaving a small fraction to avoid raising immediate suspicion. Over 130 downloads were recorded for these packages, showcasing a targeted approach to siphon off Solana's assets via automated exfiltration.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2022
770
Breach
01 Aug 2022 • Solana Labs
Solana Labs
Solana and Slope Wallet Data Breach
701
CRITICAL-69
SOL1127151122
Solana and Slope suffered from a data breach incident that affected Slope, a third-party wallet for Solana.
The hardware wallets offered by Slope are still safe; the attack only affected the downloadable wallet program.
The Solana Foundation noted that the Solana protocol itself is still secure despite the fact that thousands of wallets were drained.
Customers should take action to protect their funds, the business further advised.
It suggested that customers transfer their funds to a new wallet after creating a new seed phrase.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Solana Labs ??
What was Solana Labs's A.I Rankiteo Cyber Score in May 2026 ??
What was Solana Labs's A.I Rankiteo Cyber Score in April 2026 ??
What was Solana Labs's A.I Rankiteo Cyber Score in March 2026 ??
What was Solana Labs's A.I Rankiteo Cyber Score in February 2026 ??
What was Solana Labs's A.I Rankiteo Cyber Score in January 2026 ??
What was Solana Labs's A.I Rankiteo Cyber Score in December 2025 ??
What was Solana Labs's A.I Rankiteo Cyber Score in November 2025 ??
What was Solana Labs's A.I Rankiteo Cyber Score in October 2025 ??
What was Solana Labs's A.I Rankiteo Cyber Score in September 2025 ??
What was Solana Labs's A.I Rankiteo Cyber Score in August 2025 ??
What was Solana Labs's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Solana Labs's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Solana Labs ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Solana Labs's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?