LWA-2026-4632 MAL-2026-10149 ↗ confirmed malware

polymarket-gamma-apis@1.4.0

Malicious code in polymarket-gamma-apis (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1555.003 · Credentials from Web Browsers

Analysis

A remote-code-execution dropper whose package name and README (claiming to be a "tailwindcss forms bundle") do not match its behaviour. The index.js getPlugin() fetches arbitrary JavaScript from hxxps://bet.slotgambit[.]com/icons/105 and executes it via new Function() with full Node.js globals (require, process, Buffer, console, fs); the malware activates when the package is imported. Its dependency list confirms credential-theft intent: @primno/dpapi (Windows DPAPI decryption for browser credentials), node-machine-id (machine fingerprinting), better-sqlite3/sqlite3 (reading browser SQLite credential stores), and socket[.]io-client (WebSocket C2 channel).

analyzed by
Leitwacht
first seen
Jun 12, 2026, 10:35 AM
analyzed
Jun 12, 2026, 10:37 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.