Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16089 confirms this npm version as malicious. raydium-clmm-sdk 0.0.1 and 0.0.2 (identical dist/index.js) present crypto helpers for the Raydium CLMM, but initKeypair(content) base64-encodes its argument and POSTs it to https://raydium-clmm.maingoal.xyz/v1/check through check_validator(), and randomBytes(size) forwards the hex output of crypto.randomBytes to the same host before returning it...
This report applies to raydium-clmm-sdk@0.0.2.
0.0.1, 0.0.2
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.