Malicious code in ledger-lib (npm)
The npm package ledger-lib version 1.0.0 was identified as malicious by the OpenSSF Package Analysis project. The package communicates with a domain associated with malicious activity.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of ledger-lib 1.0.0
- Ecosystems
- Attack vectors
- Affected entities
- ledger-lib · 1.0.0
The OpenSSF Package Analysis project identified ledger-lib version 1.0.0 on npm as containing malicious code. The malicious behavior was detected through communication with a domain associated with known malicious activity.
The package was flagged and cataloged in the OpenSSF's malicious-packages repository (MAL-2026-12068). This discovery was published on GitHub's advisory database on 2026-08-05.
Users who have installed ledger-lib 1.0.0 should immediately remove or update the package. The specific malicious domain and payload details are referenced in the OpenSSF's malicious-packages repository.
Indicators of compromise
- Packages
- ledger-lib@1.0.0
Remediation
- Remove ledger-lib 1.0.0 from all projects and dependencies
- Audit systems that may have executed code from ledger-lib 1.0.0 for signs of compromise
- Check npm audit logs for installations of ledger-lib 1.0.0
- Use a package manager lock file to prevent accidental installation of the malicious version
- Monitor for any alternative malicious packages with similar names (typosquatting variants)
Sources
- GitHub Advisory GHSA-2gq8-9xc9-mx8j · GitHub Advisory Database
Cite this entry
"Malicious code in ledger-lib (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-ledger-lib-npm-bj5hrf
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in awesome-ts-jest
Malware was discovered in the npm package awesome-ts-jest. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in async-mutex-v2
Malware was discovered in the npm package async-mutex-v2. Systems with this package installed are considered fully compromised and require immediate remediation including credential rotation and package removal.
npmCompromised package - containedcritical
Malware in arc-diag-util
The npm package arc-diag-util was found to contain malware, resulting in full system compromise of any computer with the package installed or running. All secrets and keys should be rotated immediately from a different machine, and the package should be removed.
npmCompromised package - activecritical
Malware in rendezvous-js
The npm package rendezvous-js contains malware that grants full control of affected systems. Any computer with this package installed or running should be considered fully compromised.
npmCompromised package