Skip to main content

Malicious code in raydium-clmm-sdk (npm)

0
Critical
Published: 09/09/2026 (09/09/2026, 14:00:00 UTC)
Source: GCVE Database
Product: raydium-clmm-sdk

Description

The raydium-clmm-sdk npm package versions 0.0.1 and 0.0.2 contain malicious code that exfiltrates data. Specifically, the initKeypair(content) function base64-encodes its input and sends it to a remote server, and the randomBytes(size) function sends cryptographic random bytes to the same server. The package does not execute malicious code on install or import, but data is leaked upon calling these functions. The package falsely claims to contain only type definitions. Systems with this package installed should be considered fully compromised.

Affected software

npmghsa
raydium-clmm-sdk
Affected versions
=0.0.1=0.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 13:38:24 UTC

Technical Analysis

The raydium-clmm-sdk npm package versions 0.0.1 and 0.0.2 include malicious functionality where sensitive data passed to initKeypair(content) is base64-encoded and POSTed to a remote endpoint (https://raydium-clmm.maingoal.xyz/v1/check). Additionally, the randomBytes(size) function sends the hex output of crypto.randomBytes to the same endpoint before returning it. This behavior results in exfiltration of potentially sensitive cryptographic material. The package does not run malicious code on installation or import, but data leakage occurs on the first invocation of these exports. The package's README misleadingly states it contains only type definitions. The publisher and hosting domain are shared with other suspicious packages. Due to the nature of this malicious code, any system with this package installed should be treated as fully compromised.

Potential Impact

Any computer with raydium-clmm-sdk versions 0.0.1 or 0.0.2 installed or running is at risk of having sensitive cryptographic data exfiltrated to an attacker-controlled server. This compromises the confidentiality of secrets and keys on the system. Because the package sends data on function calls, secrets passed to these functions can be leaked. The compromise is severe enough that full system compromise is assumed, and all secrets should be rotated from a clean environment.

Defensive Guidance

Immediate removal of the raydium-clmm-sdk package versions 0.0.1 and 0.0.2 is required. However, removal alone does not guarantee system integrity due to potential full compromise. All secrets and cryptographic keys stored on the affected system must be rotated from a different, trusted computer. There is no official patch or fix available. Users should avoid using this package and any related packages from the same publisher or domain.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-16089
Osv Schema Version
1.7.4
Aliases
["GHSA-cq4p-x9wg-m5wv"]
Ecosystems
["npm"]

Threat ID: 6aa2af89acd9273b4925b508

Added to database: 09/10/2026, 13:24:25 UTC

Last enriched: 09/10/2026, 13:38:24 UTC

Last updated: 09/11/2026, 14:32:04 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses