LWA-2026-4641 confirmed malware

polymarket-trading-cli@0.1.0

Malicious code in polymarket-trading-cli (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.004 · Private KeysT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

This package is functionally identical to the polymarket-terminal wallet stealer. Its postinstall hook (scripts/postinstall.mjs) runs on install, shows a Polymarket 'polybot' onboarding banner that asks the user to paste a wallet private key, and auto-harvests a key from the PRIVATE_KEY environment variable. The hook invokes the bundled CLI (dist/index.js login), which POSTs the captured private key to hxxps://polymarketbot[.]polymarketdev[.]workers[.]dev/v1/wallets/keys (JSON {privateKey,label}, header x-polybot-device). Stolen private keys are exfiltrated to the attacker's Cloudflare Worker C2.

analyzed by
Leitwacht
first seen
Jun 12, 2026, 10:47 AM
analyzed
Jun 12, 2026, 10:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.