LWA-2026-4631 confirmed malware
polymarket-gamma-api@1.4.9
Malicious code in polymarket-gamma-api (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
A trojan masquerading as a Polymarket API integration with no actual Polymarket functionality. The index.js exports getPlugin(), which fetches a second-stage payload from hxxps://bet.slotgambit[.]com/icons/109 and executes it via new Function() with full Node.js context (require, process, Buffer, global) at import time, acting as a remote-code loader that downloads and runs arbitrary code.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 10:34 AM
- analyzed
- Jun 12, 2026, 10:37 AM
Related advisories
- polymarket-gamma-apis@1.4.0
- polygon-bitquery-apis@2.2.3
- node-path-utils@1.23.2
- peptideenv@16.6.6
- vite-react-toolkit@1.0.1
- payments-ui-services@45.0.0
- pathfix@3.0.7
- passport-local-strategy@3.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.