Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@solana-labs/spl-tokenpm

@solana-labs/spl-toke is a confirmed malicious npm package (MAL-2026-5787) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.2, 1.0.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @solana-labs/spl-toke (npm)

MAL-2026-5787
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @solana-labs/spl-toke

What this malware does

Package name @solana-labs/spl-toke is a likely confusion-attack against the well-known @solana/spl-token SPL token client (missing trailing n, different scope). The shipped lib/index.cjs.js and lib/index.esm.js bundles contain the keyword combinations fetch( / POST / https.get / ping that pattern-matched as potential C2 / exfiltration shapes, but tracing of the minified bundle did not complete and the literal destination URLs and trigger paths could not be confirmed in this run. The ping token may be benign (e.g. a websocket keepalive method or solana RPC ping helper) and the fetch calls may be ordinary RPC traffic — but neither has been verified, and combined with the typosquat-shaped name on a high-value scope (@solana-labs/* mimicking the official solana-labs GitHub org and the canonical @solana/spl-token package), this needs human review before installer use.

Malicious versions

17 flagged
1.0.01.0.21.0.31.0.41.0.51.0.61.0.71.0.81.0.101.98.1031.98.1051.98.1071.98.1081.98.1091.98.1101.98.1111.98.112

Indicators of compromise (SHA-256)

0a75812030937ae0ecf6c5d267667b2454058a324711bf3280ed3e97eb5f8b5a
f92bf1c5408d5c80d1bb78242f7315df61273713e07dfad4892f01d0c451e916
0b23badd2ad9e0607dabb4d58bc78762691e31c58c9b548db11e0543e21d40fc
5e83e440dfb72440a6534ecc320ef618b829630c5cb0fbed432f1237fd45f9ec
75b8b946808d1c68fd9c479993b8ed19b103030b3d37a6feeba099f6d4c02b62
d10819a7af9f7f0fd57651626b41a13492ba3841206caa870fdcfbbb0516836b
96715c34660630d56f91507a3de9fe64c47de50c19afe8de61107ecc78a0ac38
a91d0a65c4acdc298a7775a0f4a2e3a65dd07ede8c4731fabefce12525ae38e6
ae699ea42c65454a0a9fd55bfd47f9eb9647b9a2dcc604ddd4296cf5a72a32ce
f4473251be335760795fc2692450b59c06efa8a7227daf3c2d384cd26f1808d5
16921c38f633d6edf7d7207cdc7cb695891a2f6d8cc6f234144a9ca4f3bd90a0
1e6354850b8587cc5b396376a5401bbe99f34df134f815a39c9690e37a21e75f
490ce5d7e43d8a79aa85bbd24e7140ed074eee472f375092ab9b4cd650ce41f8
4c3108856cfed00df1ae55c038ee7354339ba02864924e43baefb1ca13499531
6962bb20fc11a76d4a8235c0cf55f36a941167d4cae085e5a391ea7637b8ceb6
e56cb6f556b8a711af49f2feabc153d8d20fc9f410db77a5da2855382f946803
bc01c00946b67ed7f24c792e734b53e3ee2445339606f3c375088b1f7b92ccaf
8996ddebfde092bd8e1100f01e45fe963327c4c8c403ea67176098b5e2f0e26e
8e2ec34996ab8cff20d9ba12cd9f5a8a75346c4e5e25d7c3fd5adc7bb7045f64
c1f53529715bb98b15f1131c24a4765f1299459e24b5702df991ba4cf553f1b6
f09ab1a7bdb9c54cb863c619655b98bbdfdbde645ed60392c15c118d20442426
0a8c3729a5a54157a3e7ed4d93db482e430156ff3cb550a47867a3c7de6eae5c
2566ae060700bc91103623a762f99328266339c99b06ec2a309eda354267a6e0
4db530bb06064fcb6281e9915b52fa876677fe518c249584b59bec0149b48e2d
6f9674353cb2d3d209e6e49bca0a12c4189947398600f1a4cdb2a160b7a0dd07

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @solana-labs/spl-toke (17 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @solana-labs/spl-toke across your stack and pipelines.

  2. If you installed it — respond

    @solana-labs/spl-toke is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @solana-labs/spl-toke was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @solana-labs/spl-toke before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @solana-labs/spl-toke on npm has been identified as a malicious package (versions 1.0.0, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, and 9 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-006587IN-MAL-2026-006575IN-MAL-2026-006581IN-MAL-2026-006577IN-MAL-2026-006579IN-MAL-2026-006574IN-MAL-2026-006584IN-MAL-2026-006582IN-MAL-2026-006573IN-MAL-2026-006586IN-MAL-2026-006585IN-MAL-2026-006580IN-MAL-2026-006576IN-MAL-2026-006578IN-MAL-2026-006588IN-MAL-2026-006583RLMA-2026-05467IN-MAL-2026-012943IN-MAL-2026-012977IN-MAL-2026-012919IN-MAL-2026-012947IN-MAL-2026-012983IN-MAL-2026-012984IN-MAL-2026-012975IN-MAL-2026-012940

References

Credits

  • Amazon Inspector · finder
  • ReversingLabs · finder

Detect & block this

O3 blocks @solana-labs/spl-toke-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@solana-labs/spl-toke (npm) malicious package — MAL-2026-5787 | O3 Security