polygon-gamma-apis@1.5.2
Malicious code in polygon-gamma-apis (npm)
Analysis
polygon-gamma-apis is a combosquat of the polymarket-clob-api SDK (the package's own README is a verbatim copy of the real SDK's documentation). The package contains a remote-code-execution dropper in index.js: the exported getPlugin() function fetches a JSON payload from hxxps://svganchordev[.]net/icons/111 (with the request header 'bearrtoken: logo') and passes the response's 'credits' field into a new Function() constructor injected with the full set of Node.js globals — including require (granting access to child_process, fs, and all system APIs). This allows the remote server to execute arbitrary code on any machine that requires this package. The host svganchordev[.]net serves the remotely-controlled second-stage payload. The package also ships dependencies suitable for system fingerprinting (node-machine-id) and Windows credential access (@primno/dpapi), alongside socket[.]io-client, better-sqlite3, express, and axios, providing a full attack toolchain.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 03:23 AM
- analyzed
- Jul 3, 2026, 03:25 AM
Related advisories
- execfences@5.0.2
- compose-logger-stand@1.0.126
- chalk-plus-ts@1.0.4
- assertcoreutils@2.3.2
- pino-zod@1.0.121
- zod-pino@1.0.122
- panrouter-admin@5.0.0
- hex-conv-ae7a@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.