
Research
/Security News
npm Package Uses Prompt Injection and Token Flooding to Disrupt AI Malware Scanners
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.
@chainstream-io/pumpdotfun-sdk
Advanced tools
Never click links in this repository leaving github, never click links in Issues, don't run code that others post without reading it, this software is provided "as is," without warranty.
The PumpDotFunSDK is designed to interact with the Pump.fun decentralized application. It provides methods for creating, buying, and selling tokens using the Solana blockchain. The SDK handles the necessary transactions and interactions with the Pump.fun program.
npm i pumpdotfun-sdk
First you need to create a .env file and set your RPC URL like in the .env.example
Then you need to fund an account with atleast 0.004 SOL that is generated when running the command below
npx ts-node example/basic/index.ts
import dotenv from "dotenv";
import { Connection, Keypair, LAMPORTS_PER_SOL } from "@solana/web3.js";
import { DEFAULT_DECIMALS, PumpFunSDK } from "pumpdotfun-sdk";
import NodeWallet from "@coral-xyz/anchor/dist/cjs/nodewallet";
import { AnchorProvider } from "@coral-xyz/anchor";
import {
getOrCreateKeypair,
getSPLBalance,
printSOLBalance,
printSPLBalance,
} from "./util";
dotenv.config();
const KEYS_FOLDER = __dirname + "/.keys";
const SLIPPAGE_BASIS_POINTS = 100n;
const getProvider = () => {
if (!process.env.HELIUS_RPC_URL) {
throw new Error("Please set HELIUS_RPC_URL in .env file");
}
const connection = new Connection(process.env.HELIUS_RPC_URL || "");
const wallet = new NodeWallet(new Keypair());
return new AnchorProvider(connection, wallet, { commitment: "finalized" });
};
const createAndBuyToken = async (sdk, testAccount, mint) => {
const tokenMetadata = {
name: "TST-7",
symbol: "TST-7",
description: "TST-7: This is a test token",
filePath: "example/basic/random.png",
};
const createResults = await sdk.createAndBuy(
testAccount,
mint,
tokenMetadata,
BigInt(0.0001 * LAMPORTS_PER_SOL),
SLIPPAGE_BASIS_POINTS,
{
unitLimit: 250000,
unitPrice: 250000,
}
);
if (createResults.success) {
console.log("Success:", `https://pump.fun/${mint.publicKey.toBase58()}`);
printSPLBalance(sdk.connection, mint.publicKey, testAccount.publicKey);
} else {
console.log("Create and Buy failed");
}
};
const buyTokens = async (sdk, testAccount, mint) => {
const buyResults = await sdk.buy(
testAccount,
mint.publicKey,
BigInt(0.0001 * LAMPORTS_PER_SOL),
SLIPPAGE_BASIS_POINTS,
{
unitLimit: 250000,
unitPrice: 250000,
}
);
if (buyResults.success) {
printSPLBalance(sdk.connection, mint.publicKey, testAccount.publicKey);
console.log("Bonding curve after buy", await sdk.getBondingCurveAccount(mint.publicKey));
} else {
console.log("Buy failed");
}
};
const sellTokens = async (sdk, testAccount, mint) => {
const currentSPLBalance = await getSPLBalance(
sdk.connection,
mint.publicKey,
testAccount.publicKey
);
console.log("currentSPLBalance", currentSPLBalance);
if (currentSPLBalance) {
const sellResults = await sdk.sell(
testAccount,
mint.publicKey,
BigInt(currentSPLBalance * Math.pow(10, DEFAULT_DECIMALS)),
SLIPPAGE_BASIS_POINTS,
{
unitLimit: 250000,
unitPrice: 250000,
}
);
if (sellResults.success) {
await printSOLBalance(sdk.connection, testAccount.publicKey, "Test Account keypair");
printSPLBalance(sdk.connection, mint.publicKey, testAccount.publicKey, "After SPL sell all");
console.log("Bonding curve after sell", await sdk.getBondingCurveAccount(mint.publicKey));
} else {
console.log("Sell failed");
}
}
};
const main = async () => {
try {
const provider = getProvider();
const sdk = new PumpFunSDK(provider);
const connection = provider.connection;
const testAccount = getOrCreateKeypair(KEYS_FOLDER, "test-account");
const mint = getOrCreateKeypair(KEYS_FOLDER, "mint");
await printSOLBalance(connection, testAccount.publicKey, "Test Account keypair");
const globalAccount = await sdk.getGlobalAccount();
console.log(globalAccount);
const currentSolBalance = await connection.getBalance(testAccount.publicKey);
if (currentSolBalance === 0) {
console.log("Please send some SOL to the test-account:", testAccount.publicKey.toBase58());
return;
}
console.log(await sdk.getGlobalAccount());
let bondingCurveAccount = await sdk.getBondingCurveAccount(mint.publicKey);
if (!bondingCurveAccount) {
await createAndBuyToken(sdk, testAccount, mint);
bondingCurveAccount = await sdk.getBondingCurveAccount(mint.publicKey);
}
if (bondingCurveAccount) {
await buyTokens(sdk, testAccount, mint);
await sellTokens(sdk, testAccount, mint);
}
} catch (error) {
console.error("An error occurred:", error);
}
};
main();
The PumpDotFunSDK class provides methods to interact with the PumpFun protocol. Below are the method signatures and their descriptions.
async createAndBuy(
creator: Keypair,
mint: Keypair,
createTokenMetadata: CreateTokenMetadata,
buyAmountSol: bigint,
slippageBasisPoints: bigint = 500n,
priorityFees?: PriorityFee,
commitment: Commitment = DEFAULT_COMMITMENT,
finality: Finality = DEFAULT_FINALITY
): Promise<TransactionResult>
creator: The keypair of the token creator.mint: The keypair of the mint account.createTokenMetadata: Metadata for the token.buyAmountSol: Amount of SOL to buy.slippageBasisPoints: Slippage in basis points (default: 500).priorityFees: Priority fees (optional).commitment: Commitment level (default: DEFAULT_COMMITMENT).finality: Finality level (default: DEFAULT_FINALITY).TransactionResult.async buy(
buyer: Keypair,
mint: PublicKey,
buyAmountSol: bigint,
slippageBasisPoints: bigint = 500n,
priorityFees?: PriorityFee,
commitment: Commitment = DEFAULT_COMMITMENT,
finality: Finality = DEFAULT_FINALITY
): Promise<TransactionResult>
buyer: The keypair of the buyer.mint: The public key of the mint account.buyAmountSol: Amount of SOL to buy.slippageBasisPoints: Slippage in basis points (default: 500).priorityFees: Priority fees (optional).commitment: Commitment level (default: DEFAULT_COMMITMENT).finality: Finality level (default: DEFAULT_FINALITY).TransactionResult.async sell(
seller: Keypair,
mint: PublicKey,
sellTokenAmount: bigint,
slippageBasisPoints: bigint = 500n,
priorityFees?: PriorityFee,
commitment: Commitment = DEFAULT_COMMITMENT,
finality: Finality = DEFAULT_FINALITY
): Promise<TransactionResult>
seller: The keypair of the seller.mint: The public key of the mint account.sellTokenAmount: Amount of tokens to sell.slippageBasisPoints: Slippage in basis points (default: 500).priorityFees: Priority fees (optional).commitment: Commitment level (default: DEFAULT_COMMITMENT).finality: Finality level (default: DEFAULT_FINALITY).TransactionResult.addEventListener<T extends PumpFunEventType>(
eventType: T,
callback: (event: PumpFunEventHandlers[T], slot: number, signature: string) => void
): number
eventType: The type of event to listen for.callback: The callback function to execute when the event occurs.removeEventListener(eventId: number): void
eventId: The identifier of the event listener to remove.To run the basic example for creating, buying, and selling tokens, use the following command:
npx ts-node example/basic/index.ts
This example demonstrates how to set up event subscriptions using the PumpFun SDK.
example/events/events.tsimport dotenv from "dotenv";
import { Connection, Keypair } from "@solana/web3.js";
import { PumpFunSDK } from "pumpdotfun-sdk";
import NodeWallet from "@coral-xyz/anchor/dist/cjs/nodewallet";
import { AnchorProvider } from "@coral-xyz/anchor";
dotenv.config();
const getProvider = () => {
if (!process.env.HELIUS_RPC_URL) {
throw new Error("Please set HELIUS_RPC_URL in .env file");
}
const connection = new Connection(process.env.HELIUS_RPC_URL || "");
const wallet = new NodeWallet(new Keypair());
return new AnchorProvider(connection, wallet, { commitment: "finalized" });
};
const setupEventListeners = async (sdk) => {
const createEventId = sdk.addEventListener("createEvent", (event, slot, signature) => {
console.log("createEvent", event, slot, signature);
});
console.log("Subscribed to createEvent with ID:", createEventId);
const tradeEventId = sdk.addEventListener("tradeEvent", (event, slot, signature) => {
console.log("tradeEvent", event, slot, signature);
});
console.log("Subscribed to tradeEvent with ID:", tradeEventId);
const completeEventId = sdk.addEventListener("completeEvent", (event, slot, signature) => {
console.log("completeEvent", event, slot, signature);
});
console.log("Subscribed to completeEvent with ID:", completeEventId);
};
const main = async () => {
try {
const provider = getProvider();
const sdk = new PumpFunSDK(provider);
// Set up event listeners
await setupEventListeners(sdk);
} catch (error) {
console.error("An error occurred:", error);
}
};
main();
To run the event subscription example, use the following command:
npx ts-node example/events/events.ts
We welcome contributions! Please submit a pull request or open an issue to discuss any changes.
This project is licensed under the MIT License - see the LICENSE file for details.
Here is a sample "Use at Your Own Risk" disclaimer for a GitHub repository:
This software is provided "as is," without warranty of any kind, express or implied, including but not limited to the warranties of merchantability, fitness for a particular purpose, and noninfringement. In no event shall the authors or copyright holders be liable for any claim, damages, or other liability, whether in an action of contract, tort, or otherwise, arising from, out of, or in connection with the software or the use or other dealings in the software.
Use at your own risk. The authors take no responsibility for any harm or damage caused by the use of this software. Users are responsible for ensuring the suitability and safety of this software for their specific use cases.
By using this software, you acknowledge that you have read, understood, and agree to this disclaimer.
Feel free to customize it further to suit the specific context and requirements of your project.
By following this README, you should be able to install the PumpDotFun SDK, run the provided examples, and understand how to set up event listeners and perform token operations.
FAQs
A simple SDK for interacting with pumpdotfun
The npm package @chainstream-io/pumpdotfun-sdk receives a total of 6 weekly downloads. As such, @chainstream-io/pumpdotfun-sdk popularity was classified as not popular.
We found that @chainstream-io/pumpdotfun-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.

Product
Socket now detects supply chain risks in project manifests, starting with missing lockfiles that can make dependency installs non-reproducible.

Research
/Security News
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.