polygon-gama-apis@1.4.1
Malicious code in polygon-gama-apis (npm)
Analysis
polygon-gama-apis@1.4.1 is a combosquat package that functions as a remote code execution dropper. Its index.js exports a getPlugin() function that fetches a payload from hxxps://bet[.]slotgambit[.]com/icons/111 and executes the response's "credits" field via new Function() with full Node.js runtime access (require, process, Buffer, console, setTimeout). The C2 host is bet[.]slotgambit[.]com, path /icons/. The package has no lifecycle hooks but the dropper activates when getPlugin() is called. The README is a copy-paste describing a different package and references a non-existent GitHub repository.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 01:34 AM
- analyzed
- Jul 3, 2026, 01:35 AM
Related advisories
- notifier-utils@1.3.7
- chai-chain-dom@1.3.7
- better-tailwindcss@4.6.3
- transform-es2015-sticky-regex@6.24.3
- chai-await-dom@1.3.7
- chai-as-align@7.1.0
- db-query-log@1.0.2
- marked-prettier@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.