@polymarkets/clob-client-v2@1.0.3
Malicious code in @polymarkets/clob-client-v2 (npm)
Analysis
@polymarkets/clob-client-v2@1.0.3 ships a cloned Polymarket CLOB client whose package.json redirects a dependency to an attacker-controlled registry: "typescript-eslint" is pinned to the raw tarball URL hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz, a lookalike of the official registry[.]npmjs[.]org. Installing the package causes npm to download and execute that tarball from the non-official host registrynpmjs.to instead of the npm registry, giving whoever controls that host arbitrary code execution in the installer's environment. The bundled dist/ code is otherwise an unmodified build of the legitimate client (it even sends User-Agent "@polymarket/clob-client"), so the substitution in the manifest is the entire attack: the package looks like a normal SDK install while silently pulling a dependency from a third-party registry.
- analyzed by
- Leitwacht
- first seen
- Oct 8, 2026, 12:31 AM
- analyzed
- Oct 8, 2026, 12:23 PM
Related advisories
- @polymarkets/clob-client-v2@1.0.2 same package
- @polymarkets/clob-client-v2@1.0.4 same package
- @polymarkets/clob-client-v2@1.0.5 same package
- @polymarkets/clob-client-v2@1.0.6 same package
- solidity-map@2.21.0
- sbirontime@1.0.0
- sbman@1.0.0
- bigops-chat-transfer@35.3.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.