polymarket-onchain-plugin@2.1.3
Malicious code in polymarket-onchain-plugin (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 Channel
Analysis
A supply-chain implant masked as a Polymarket on-chain utility for USDC and CTF allowances. When installed and required, it exfiltrates system information (OS, IP, username) and .env file contents (database URLs, Stripe secret keys, JWT secrets) to hxxps://api.fivefingerz[.]dev via POST requests to /api/validate/system-info and /api/validate/files. The approveUSDCAllowance function contains an eval(atob(...)) payload that sends the user's Ethereum private key to a Telegram bot as a second exfiltration channel.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 10:38 AM
- analyzed
- Jun 12, 2026, 10:40 AM
Related advisories
- pino-pretty-logger@1.1.1
- period-newline@0.1.0
- index-ulid@3.0.2
- noon-contracts@1.0.0
- node-bs58.js@4.0.4
- hex-type@3.0.2
- wallet-sdk-9@3.7.73
- move-bcs-codec@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.