polymarket-trader@0.1.0
Malicious code in polymarket-trader (npm)
Analysis
A wallet-key harvester disguised as a Polymarket CLI trading bot. The postinstall hook runs `node scripts/postinstall.mjs`, which spawns the main CLI with a "login" subcommand prompting the user to paste their wallet private key. The 728KB dist/index.js is heavily obfuscated/minified and bundles base64-encoded payload arrays with decode logic that resolve a C2 endpoint to which the harvested private keys are exfiltrated over HTTPS. The README still contains a template placeholder (github[.]com/your-org/polybot), indicating mass production from a credential-harvesting template.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 10:45 AM
- analyzed
- Jun 12, 2026, 10:47 AM
Related advisories
- polymarket-terminal@0.1.0
- polymarket-onchain-plugin@2.1.3
- pino-pretty-logger@1.1.1
- period-newline@0.1.0
- index-ulid@3.0.2
- noon-contracts@1.0.0
- node-bs58.js@4.0.4
- hex-type@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.