polymarket-trading-developer-tool@0.1.2
Malicious code in polymarket-trading-developer-tool (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook (scripts/install-check.cjs) fetches a JSON configuration from hxxps://pm-trading-dev-tools-be[.]vercel[.]app/config/clob-math[.]json, extracts a bundle URL from the response, downloads a remote .tgz archive, extracts it into a .peer/ directory, runs npm install on the extracted bundle, and then loads and executes peer-math.js from it. This gives the attacker full remote code execution on every install, with the payload served dynamically from the attacker-controlled Vercel endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 10:12 AM
- analyzed
- Jul 2, 2026, 10:12 AM
Related advisories
- eslint-jest@4.0.6
- eslint-jest@4.0.5
- chain-chai-await@1.3.5
- svgson-lite@1.0.4
- svgcraft-core@1.0.1
- notify-theme@1.3.5
- chain-chai-async@1.3.5
- notifier-log@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.