LWA-2026-12691 confirmed malware

@polymarkets/clob-client-v2@1.0.4

Malicious code in @polymarkets/clob-client-v2 (npm)

T1195.002 · Compromise Software Supply ChainT1036 · Masquerading

Analysis

@polymarkets/clob-client-v2 is a combosquat of the legitimate Polymarket CLOB SDK (@polymarket/clob-client): the scope adds an "s" and the name adds a "-v2" suffix, while the shipped dist/ is a clone of the real client's source (viem order builders, HMAC request signing, axios HTTP helpers, ClobAuth typed-data signing). The malicious element is in package.json: the dependency "typescript-eslint" is pinned to a tarball URL on registrynpmjs.to — hxxps://registrynpmjs[.]to/typescript-eslint-8[.]58[.]2[.]tgz — a look-alike of the official registry[.]npmjs[.]org. Installing this package therefore downloads and installs an attacker-controlled tarball from that host, giving the operator arbitrary code execution in the installer's environment and a foothold in the dependency tree. The package itself carries no lifecycle hooks; the payload is delivered through the substituted dependency rather than the package's own code.

analyzed by
Leitwacht
first seen
Oct 8, 2026, 12:31 AM
analyzed
Oct 8, 2026, 12:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.