npm · Malicious package advisory
Malware@ra-ide/ld-frontend
MAL-2025-190592
Malicious code in @ra-ide/ld-frontend (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (aec551eb9431424b0e79cb127427880ebd5c21b9deb2b8d4a378fb650fb45a84) The package @ra-ide/ld-frontend was found to contain malicious code. ## Source: ossf-package-analysis (19a25a7ed0444ab3035d86c1388eb0ed5c87c2c4162ac0f9f57c1def30b5019d) The OpenSSF Package Analysis project identified '@ra-ide/ld-frontend' @ 141.3.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Compromised versions (1)
- 141.3.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.