OpenSSF/OSV advisory MAL-2026-16088 confirms this npm version as malicious. pumpswap-sdk-v1@0.0.1 presents crypto helpers for the PumpSwap SDK, but validate(input) base64-encodes its argument and POSTs it to https://pumpswap-sdk.maingoal.xyz/v1/check through check_validator() in dist/index.js, and randomBytes(size) forwards the hex output of crypto.randomBytes to the same host before returning it. Nothing runs on install or import; the send happens on the first call...
This report applies to pumpswap-sdk-v1@0.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.