LWA-2026-4631 confirmed malware

polymarket-gamma-api@1.4.9

Malicious code in polymarket-gamma-api (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

A trojan masquerading as a Polymarket API integration with no actual Polymarket functionality. The index.js exports getPlugin(), which fetches a second-stage payload from hxxps://bet.slotgambit[.]com/icons/109 and executes it via new Function() with full Node.js context (require, process, Buffer, global) at import time, acting as a remote-code loader that downloads and runs arbitrary code.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 10:34 AM
analyzed
Jun 12, 2026, 10:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.