polymarket-gamma-apis@1.4.0
Malicious code in polymarket-gamma-apis (npm)
Analysis
A remote-code-execution dropper whose package name and README (claiming to be a "tailwindcss forms bundle") do not match its behaviour. The index.js getPlugin() fetches arbitrary JavaScript from hxxps://bet.slotgambit[.]com/icons/105 and executes it via new Function() with full Node.js globals (require, process, Buffer, console, fs); the malware activates when the package is imported. Its dependency list confirms credential-theft intent: @primno/dpapi (Windows DPAPI decryption for browser credentials), node-machine-id (machine fingerprinting), better-sqlite3/sqlite3 (reading browser SQLite credential stores), and socket[.]io-client (WebSocket C2 channel).
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 10:35 AM
- analyzed
- Jun 12, 2026, 10:37 AM
Related advisories
- pocbitbarrontest@1.0.0
- period-newline@0.1.0
- index-ulid@3.0.2
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- streak-cache-map@1.0.0
- streak-math-calc@1.0.0
- approval-guardian@1.0.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.