polymarket-trader-apis@0.1.0
Malicious code in polymarket-trader-apis (npm)
Analysis
polymarket-trader-apis is a combosquat of the legitimate Polymarket prediction-market platform. The package's main entry point (index.js) fetches remote code from hxxps://svganchordev[.]net/icons/108 and executes it via the Function constructor with full Node.js runtime access (require, process, Buffer, console, setTimeout). The fetched payload (data.credits) runs in a context that includes all Node.js globals, enabling arbitrary code execution. The package declares dependencies that form a credential-theft toolkit: @primno/dpapi (Windows credential extraction), better-sqlite3 and sqlite3 (browser credential-database access), node-machine-id (device fingerprinting), and socket[.]io-client (real-time C2 channel). The README describes a fake Polymarket trading utility, but the code performs no trading functions — it is a remote-code-execution dropper. C2: svganchordev[.]net, path /icons/{token}.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 02:46 PM
- analyzed
- Jul 3, 2026, 02:48 PM
Related advisories
- polymarket-apis@1.1.0
- yiyuan-api@1.0.3
- polygon-gamma-apis@1.5.2
- ue-jenkins-buildkite@99999.0.0
- epic-internal-tools@99999.0.0
- robomerge@99999.0.0
- compose-logger-stand@1.0.126
- cursed-ecto-d3ab00@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.