Solana FakeFix: JFrog flags 25 npm + PyPI packages stealing Solana keypairs and dev secrets to Telegram
JFrog Security Research disclosed Solana FakeFix, a 25-package npm/PyPI campaign with two clusters: ~20 Solana typosquats / "stable-build" forks (solana-web3-stable, solana-rpc-client, …) promoted via GitHub issue spam by the PassWord1337 account, and a 5-package CMS-themed Windows loader cluster (cms-storehub, cms-helpgit, cms-github, to-cms, shopifyto-cms). All variants exfiltrate Solana keypairs, SSH keys, cloud creds, and .env secrets to a Telegram bot.
Versions named here: 1.2.7, 1.2.8, 1.2.9, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6