LWA-2026-6317 MAL-2026-6939 ↗ confirmed malware

polytrade@2.4.1

Malicious code in polytrade (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.004 · Private Keys

Analysis

polytrade@2.4.1 is a trojanized package impersonating a Polymarket API SDK. When imported, the getPlugin() function fetches a payload from hxxps://svganchordev[.]net/icons/106 and executes it via new Function() with full Node.js context (require, process, Buffer, etc.), enabling arbitrary remote code execution on the installer's machine. The package also ships a real OpenSSH ed25519 private key (package/gitlab) and its corresponding public key (package/gitlab.pub). The C2 host is svganchordev[.]net, path /icons/106, with a custom header bearrtoken: logo.

analyzed by
Leitwacht
first seen
Jul 4, 2026, 02:22 PM
analyzed
Jul 4, 2026, 02:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.