polytrade@2.4.1
Malicious code in polytrade (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.004 · Private Keys
Analysis
polytrade@2.4.1 is a trojanized package impersonating a Polymarket API SDK. When imported, the getPlugin() function fetches a payload from hxxps://svganchordev[.]net/icons/106 and executes it via new Function() with full Node.js context (require, process, Buffer, etc.), enabling arbitrary remote code execution on the installer's machine. The package also ships a real OpenSSH ed25519 private key (package/gitlab) and its corresponding public key (package/gitlab.pub). The C2 host is svganchordev[.]net, path /icons/106, with a custom header bearrtoken: logo.
- analyzed by
- Leitwacht
- first seen
- Jul 4, 2026, 02:22 PM
- analyzed
- Jul 4, 2026, 02:23 PM
Related advisories
- ripshakti1@81.0.0
- anthropic-internal-tools@1.0.0
- @epsteinlovekids483/crossmint-wallets-sdk-pentest@1.0.0-pentest
- react-campaign-optimizer@1.0.0
- @npmresearch3/metrics-probe-dfda@1.0.0
- atlasora-utils@1.0.0
- atlasora-types@1.0.0
- atlasora-sdk@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.