Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in ledger-lib (npm)

The npm package ledger-lib version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on adoption of ledger-lib 1.0.0
Ecosystems
Attack vectors
Affected entities
  • ledger-lib · 1.0.0

The OpenSSF Package Analysis project identified ledger-lib version 1.0.0 on npm as containing malicious code. The malicious behavior was detected through communication with a domain associated with known malicious activity.

The package was flagged and cataloged in the OpenSSF's malicious-packages repository (MAL-2026-12068). This discovery was published on GitHub's advisory database on 2026-08-05.

Users who have installed ledger-lib 1.0.0 should immediately remove or update the package. The specific malicious domain and payload details are referenced in the OpenSSF's malicious-packages repository.

Indicators of compromise

Packages
  • ledger-lib@1.0.0

Remediation

  • Remove ledger-lib 1.0.0 from all projects and dependencies
  • Audit systems that may have executed code from ledger-lib 1.0.0 for signs of compromise
  • Check npm audit logs for installations of ledger-lib 1.0.0
  • Use a package manager lock file to prevent accidental installation of the malicious version
  • Monitor for any alternative malicious packages with similar names (typosquatting variants)

Sources

  1. GitHub Advisory GHSA-2gq8-9xc9-mx8j · GitHub Advisory Database

Cite this entry

"Malicious code in ledger-lib (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-ledger-lib-npm-bj5hrf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in awesome-ts-jest

    Malware was discovered in the npm package awesome-ts-jest. Systems with this package installed or running should be considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in async-mutex-v2

    Malware was discovered in the npm package async-mutex-v2. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.

    npmCompromised package
  3. containedcritical

    Malware in arc-diag-util

    The npm package arc-diag-util was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different machine, and the package should be removed.

    npmCompromised package
  4. activecritical

    Malware in rendezvous-js

    The npm package rendezvous-js contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.

    npmCompromised package