LWA-2026-6613 MAL-2026-10199 ↗ confirmed malware

polymarket-kelly-math-stake@3.6.2

Malicious code in polymarket-kelly-math-stake (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook in scripts/install-check.cjs fetches a remote JSON config from jipred[.]vercel[.]app, extracts a bundle URL from it, downloads a .tgz archive, extracts it into a .peer/ directory, runs npm install on the extracted content, and then requires and executes peer-math.js from the downloaded bundle. This is a multi-stage remote code execution payload that downloads and runs arbitrary code at install time. The package's index.js and kelly.js are benign decoy math functions; the malicious behaviour is entirely in the postinstall script.

analyzed by
Leitwacht
first seen
Jul 11, 2026, 09:18 AM
analyzed
Jul 11, 2026, 09:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.