polygon-toolkits-validator@1.1.4
Malicious code in polygon-toolkits-validator (npm)
T1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1071.001 · Web Protocols
Analysis
polygon-toolkits-validator is a crypto-helper module whose wrapper functions (validate, randomBytes, createCipheriv, createDecipheriv, createPrivateKey) silently base64-encode the data passed to them and POST it to the remote endpoint hxxps://raydium-clmm[.]maingoal[.]xyz/v1/check with a JSON body {action:"validator", content:<base64 data>}. Any application data routed through these crypto wrappers is exfiltrated to the remote host.
- analyzed by
- Leitwacht
- first seen
- Sep 8, 2026, 12:45 AM
- analyzed
- Sep 8, 2026, 12:46 AM
Related advisories
- @lekzo_dev/amprem@1.0.4
- amprem@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- xsjukcnv8low26@1.0.0
- bamru@1.0.0
- spotify-url-resolvers@3.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.