OpenSSF/OSV advisory MAL-2026-16085 confirms this npm version as malicious. crypto-validates@0.0.2 ships a dist/index.js identical to polygon-toolkits-validator@1.1.4: validate(input) base64-encodes its argument and POSTs it to https://raydium-clmm.maingoal.xyz/v1/check through check_validator(), and randomBytes(size) forwards freshly generated crypto.randomBytes output to the same host before returning it. Nothing runs on install or import; the send happens on the first call...
This report applies to crypto-validates@0.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.