polymarket-stake-kelly-math@3.8.2
Malicious code in polymarket-stake-kelly-math (npm)
Analysis
On install, the postinstall hook (scripts/install-check.cjs) fetches a JSON config from hxxps://jipred[.]vercel[.]app/config/clob-math[.]json, reads a peerBundle URL from that config, downloads a .tgz archive from that URL, extracts it into a .peer/ directory inside the package, runs npm install inside .peer/, then requires peer-math.js and calls its syncSession() function. This is a multi-stage remote code execution pipeline: the attacker controls the config endpoint and can serve arbitrary second-stage payloads at install time. The package is a combosquat of the legitimate polymarket-stake-math package (the README references the wrong package name).
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 04:38 PM
- analyzed
- Jul 13, 2026, 04:39 PM
Related advisories
- polymarket-math-stake-kelly@3.7.2
- gifuct@2.1.2
- @sqlite-group/schema-generator@1.0.2
- gptlite@4.0.8
- datavaultx@1.7.1
- auth-gen-next@1.7.13
- node-sysmon-native@1.0.0
- @sof-assistant-fe-lib/vertical-faqs@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.