LWA-2026-4634 MAL-2026-6864 ↗ confirmed malware

polymarket-onchain-plugin@2.1.3

Malicious code in polymarket-onchain-plugin (npm)

T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1552.004 · Private KeysT1082 · System Information DiscoveryT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 Channel

Analysis

A supply-chain implant masked as a Polymarket on-chain utility for USDC and CTF allowances. When installed and required, it exfiltrates system information (OS, IP, username) and .env file contents (database URLs, Stripe secret keys, JWT secrets) to hxxps://api.fivefingerz[.]dev via POST requests to /api/validate/system-info and /api/validate/files. The approveUSDCAllowance function contains an eval(atob(...)) payload that sends the user's Ethereum private key to a Telegram bot as a second exfiltration channel.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 10:38 AM
analyzed
Jun 12, 2026, 10:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.