
Ideal typosquat ‘solana-py’ steals your crypto wallet keys
The legitimate Solana Python API project is known as “solana-py” on GitHub, but simply “solana” on the Python software registry, PyPI. This slight naming discrepancy has been leveraged by a threat actor who published a “solana-py” project on PyPI which, in addition to borrowing real code from the legitimate project, quietly steals your secrets, making it an ideal typosquat.
*** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/an-ideal-pypi-typosquat-solana-py-is-here-to-steal-your-crypto-keys