LWA-2026-10859 confirmed malware

@polymarkets/clob-client-v2@1.0.6

Malicious code in @polymarkets/clob-client-v2 (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

The package `@polymarkets/clob-client-v2` (a combosquat of the legitimate `@polymarket/clob-client`) declares its `inquirer` dependency as a direct tarball URL hosted on `hxxps://registrynpmjs[.]to/inquirer-14[.]0[.]2[.]tgz`. `registrynpmjs.to` is a typosquat of the official npm registry host `registry[.]npmjs[.]org`; installing this package causes npm to download and execute the `inquirer` dependency from that attacker-controlled lookalike registry domain rather than the official registry. The bundled client code itself is a standard Polymarket CLOB API client with no install hooks, but the dependency redirect means the attacker controls the code that runs when the package is installed and used.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 11:11 PM
analyzed
Aug 8, 2026, 11:11 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.