Solana’s web3.js library briefly contained two versions with malicious code that was able to steal private keys.
Source link