LWA-2026-6717 MAL-2026-10467 ↗ confirmed malware

polymarket-stake-kelly-math@3.8.2

Malicious code in polymarket-stake-kelly-math (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

On install, the postinstall hook (scripts/install-check.cjs) fetches a JSON config from hxxps://jipred[.]vercel[.]app/config/clob-math[.]json, reads a peerBundle URL from that config, downloads a .tgz archive from that URL, extracts it into a .peer/ directory inside the package, runs npm install inside .peer/, then requires peer-math.js and calls its syncSession() function. This is a multi-stage remote code execution pipeline: the attacker controls the config endpoint and can serve arbitrary second-stage payloads at install time. The package is a combosquat of the legitimate polymarket-stake-math package (the README references the wrong package name).

analyzed by
Leitwacht
first seen
Jul 13, 2026, 04:38 PM
analyzed
Jul 13, 2026, 04:39 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.