polymarket-kelly-math-stake@3.6.2
Malicious code in polymarket-kelly-math-stake (npm)
Analysis
The postinstall hook in scripts/install-check.cjs fetches a remote JSON config from jipred[.]vercel[.]app, extracts a bundle URL from it, downloads a .tgz archive, extracts it into a .peer/ directory, runs npm install on the extracted content, and then requires and executes peer-math.js from the downloaded bundle. This is a multi-stage remote code execution payload that downloads and runs arbitrary code at install time. The package's index.js and kelly.js are benign decoy math functions; the malicious behaviour is entirely in the postinstall script.
- analyzed by
- Leitwacht
- first seen
- Jul 11, 2026, 09:18 AM
- analyzed
- Jul 11, 2026, 09:19 AM
Related advisories
- supertokens-web@1.16.0
- chai-as-doc@2.3.5
- llama-tokenizer@1.2.2
- type-atob@3.3.7
- eth-react-redirection@1.0.0
- chain-js-utils@2.1.1
- note-utilities@2.1.2
- chain-await-dom@1.3.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.