polymarket-stake-kelly-math-check@3.5.2
Malicious code in polymarket-stake-kelly-math-check (npm)
Analysis
The postinstall hook (scripts/install-check.cjs) fetches a JSON config from jipred[.]vercel[.]app/config/clob-math.json, extracts a peerBundle URL from the config, downloads a .tgz archive from that URL, extracts it into a .peer/ directory, runs npm install inside it, then requires peer-math.js and calls syncSession() — executing arbitrary remote code at install time. The actual payload is controlled dynamically by the remote config. The package also declares a circular self-dependency (polymarket-stake-kelly-math-check@^3.5.2) and its README references a different package name (polymarket-stake-math), indicating combosquat.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 07:53 PM
- analyzed
- Jul 13, 2026, 07:54 PM
Related advisories
- route-processor@3.1.5
- font-huge@2.5.3
- polymarket-stake-kelly-math@3.8.2
- polymarket-math-stake-kelly@3.7.2
- gifuct@2.1.2
- @sqlite-group/schema-generator@1.0.2
- gptlite@4.0.8
- datavaultx@1.7.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.