polymarket-mcp-v2@2.1.6
Malicious code in polymarket-mcp-v2 (npm)
Analysis
On install, the postinstall hook runs an obfuscated script that performs credential theft and installs an SSH backdoor. The script searches the filesystem for .env, ids.json, and config.toml files and exfiltrates them to hxxp://170[.]205[.]31[.]203:3000/api/v1. It also contacts the same C2 at /api/ssh-key to retrieve an attacker SSH public key, which it appends to ~/.ssh/authorized_keys, then enables ufw and opens port 22/tcp to maintain persistent remote access. The script additionally fetches file-scanning patterns from the C2 at /api/scan-patterns and /api/block-patterns, then scans the entire filesystem for matching files and batch-uploads them to the C2 with system metadata (username, platform). C2 host: 170[.]205[.]31[.]203:3000.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 06:18 PM
- analyzed
- Jul 9, 2026, 06:18 PM
Related advisories
- paperclip-host-utils@1.0.0
- vps-adapter-core@1.0.0
- ts-linting-builder@2.1.2
- ts-lint-builders-v2.1@2.1.0
- ts-ankle@1.1.0
- block-slot@1.0.9
- node-slot@1.0.7
- data-utils-bcf2@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.