LWA-2026-6278 MAL-2026-10147 ↗ confirmed malware

polygon-gama-apis@1.4.1

Malicious code in polygon-gama-apis (npm)

Analysis

polygon-gama-apis@1.4.1 is a combosquat package that functions as a remote code execution dropper. Its index.js exports a getPlugin() function that fetches a payload from hxxps://bet[.]slotgambit[.]com/icons/111 and executes the response's "credits" field via new Function() with full Node.js runtime access (require, process, Buffer, console, setTimeout). The C2 host is bet[.]slotgambit[.]com, path /icons/. The package has no lifecycle hooks but the dropper activates when getPlugin() is called. The README is a copy-paste describing a different package and references a non-existent GitHub repository.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 01:34 AM
analyzed
Jul 3, 2026, 01:35 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.