polymarket-kit@2.4.1
Malicious code in polymarket-kit (npm)
Analysis
polymarket-kit@2.4.1 is a combosquat package impersonating the legitimate Polymarket SDK. When imported, index.js fetches a remote payload from hxxps://svganchordev[.]net/icons/106 and executes it via new Function() with full Node.js access (require, process, Buffer, child_process). The package ships a real SSH private key (package/gitlab, OpenSSH ED25519 format). Its dependencies include node-machine-id (host fingerprinting), @primno/dpapi (Windows credential decryption), better-sqlite3 (local database access), socket[.]io-client (C2 channel), and express/axios/request (HTTP server and client). The package has no repository and its code does not implement any Polymarket API functionality — it is a remote-code-execution dropper that runs arbitrary code from svganchordev[.]net on the importing system.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 08:24 AM
- analyzed
- Jul 9, 2026, 08:25 AM
Related advisories
- jest-formatter@1.0.0
- antsrcsrctest@1.0.0
- chai-as-const@1.4.5
- hello244b@1.0.0
- configration@2.3.5
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- zluri-ad-connector@9.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.