Malicious code in raydium-clmm-sdk (npm)
The raydium-clmm-sdk npm package versions 0.0.1 and 0.0.2 contain malicious code that exfiltrates data. Specifically, the initKeypair(content) function base64-encodes its input and sends it to a remote server, and the randomBytes(size) function sends cryptographic random bytes to the same server. The package does not execute malicious code on install or import, but data is leaked upon calling these functions. The package falsely claims to contain only type definitions. Systems with this package installed should be considered fully compromised.
AI Analysis
Technical Summary
The raydium-clmm-sdk npm package versions 0.0.1 and 0.0.2 include malicious functionality where sensitive data passed to initKeypair(content) is base64-encoded and POSTed to a remote endpoint (https://raydium-clmm.maingoal.xyz/v1/check). Additionally, the randomBytes(size) function sends the hex output of crypto.randomBytes to the same endpoint before returning it. This behavior results in exfiltration of potentially sensitive cryptographic material. The package does not run malicious code on installation or import, but data leakage occurs on the first invocation of these exports. The package's README misleadingly states it contains only type definitions. The publisher and hosting domain are shared with other suspicious packages. Due to the nature of this malicious code, any system with this package installed should be treated as fully compromised.
Potential Impact
Any computer with raydium-clmm-sdk versions 0.0.1 or 0.0.2 installed or running is at risk of having sensitive cryptographic data exfiltrated to an attacker-controlled server. This compromises the confidentiality of secrets and keys on the system. Because the package sends data on function calls, secrets passed to these functions can be leaked. The compromise is severe enough that full system compromise is assumed, and all secrets should be rotated from a clean environment.
Mitigation Recommendations
Immediate removal of the raydium-clmm-sdk package versions 0.0.1 and 0.0.2 is required. However, removal alone does not guarantee system integrity due to potential full compromise. All secrets and cryptographic keys stored on the affected system must be rotated from a different, trusted computer. There is no official patch or fix available. Users should avoid using this package and any related packages from the same publisher or domain.
Malicious code in raydium-clmm-sdk (npm)
Description
The raydium-clmm-sdk npm package versions 0.0.1 and 0.0.2 contain malicious code that exfiltrates data. Specifically, the initKeypair(content) function base64-encodes its input and sends it to a remote server, and the randomBytes(size) function sends cryptographic random bytes to the same server. The package does not execute malicious code on install or import, but data is leaked upon calling these functions. The package falsely claims to contain only type definitions. Systems with this package installed should be considered fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The raydium-clmm-sdk npm package versions 0.0.1 and 0.0.2 include malicious functionality where sensitive data passed to initKeypair(content) is base64-encoded and POSTed to a remote endpoint (https://raydium-clmm.maingoal.xyz/v1/check). Additionally, the randomBytes(size) function sends the hex output of crypto.randomBytes to the same endpoint before returning it. This behavior results in exfiltration of potentially sensitive cryptographic material. The package does not run malicious code on installation or import, but data leakage occurs on the first invocation of these exports. The package's README misleadingly states it contains only type definitions. The publisher and hosting domain are shared with other suspicious packages. Due to the nature of this malicious code, any system with this package installed should be treated as fully compromised.
Potential Impact
Any computer with raydium-clmm-sdk versions 0.0.1 or 0.0.2 installed or running is at risk of having sensitive cryptographic data exfiltrated to an attacker-controlled server. This compromises the confidentiality of secrets and keys on the system. Because the package sends data on function calls, secrets passed to these functions can be leaked. The compromise is severe enough that full system compromise is assumed, and all secrets should be rotated from a clean environment.
Defensive Guidance
Immediate removal of the raydium-clmm-sdk package versions 0.0.1 and 0.0.2 is required. However, removal alone does not guarantee system integrity due to potential full compromise. All secrets and cryptographic keys stored on the affected system must be rotated from a different, trusted computer. There is no official patch or fix available. Users should avoid using this package and any related packages from the same publisher or domain.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-16089
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-cq4p-x9wg-m5wv"]
- Ecosystems
- ["npm"]
Threat ID: 6aa2af89acd9273b4925b508
Added to database: 09/10/2026, 13:24:25 UTC
Last enriched: 09/10/2026, 13:38:24 UTC
Last updated: 09/11/2026, 14:32:04 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.