Solana FakeFix: JFrog flags 25 npm + PyPI packages stealing Solana keypairs and dev secrets to Telegram
JFrog Security Research disclosed Solana FakeFix, a 25-package npm/PyPI campaign with two clusters: ~20 Solana typosquats / "stable-build" forks (solana-web3-stable, solana-rpc-client, …) promoted via GitHub issue spam by the PassWord1337 account, and a 5-package CMS-themed Windows loader cluster (cms-storehub, cms-helpgit, cms-github, to-cms, shopifyto-cms). All variants exfiltrate Solana keypairs, SSH keys, cloud creds, and .env secrets to a Telegram bot.
Versions named here: 1.0.0, 1.0.1