LWA-2026-6480 MAL-2026-10071 ↗ confirmed malware

polymarket-kit@2.4.1

Malicious code in polymarket-kit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1552.001 · Credentials In Files

Analysis

polymarket-kit@2.4.1 is a combosquat package impersonating the legitimate Polymarket SDK. When imported, index.js fetches a remote payload from hxxps://svganchordev[.]net/icons/106 and executes it via new Function() with full Node.js access (require, process, Buffer, child_process). The package ships a real SSH private key (package/gitlab, OpenSSH ED25519 format). Its dependencies include node-machine-id (host fingerprinting), @primno/dpapi (Windows credential decryption), better-sqlite3 (local database access), socket[.]io-client (C2 channel), and express/axios/request (HTTP server and client). The package has no repository and its code does not implement any Polymarket API functionality — it is a remote-code-execution dropper that runs arbitrary code from svganchordev[.]net on the importing system.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 08:24 AM
analyzed
Jul 9, 2026, 08:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.