LWA-2026-6720 MAL-2026-10485 ↗ confirmed malware

polymarket-stake-kelly-math-check@3.5.2

Malicious code in polymarket-stake-kelly-math-check (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The postinstall hook (scripts/install-check.cjs) fetches a JSON config from jipred[.]vercel[.]app/config/clob-math.json, extracts a peerBundle URL from the config, downloads a .tgz archive from that URL, extracts it into a .peer/ directory, runs npm install inside it, then requires peer-math.js and calls syncSession() — executing arbitrary remote code at install time. The actual payload is controlled dynamically by the remote config. The package also declares a circular self-dependency (polymarket-stake-kelly-math-check@^3.5.2) and its README references a different package name (polymarket-stake-math), indicating combosquat.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 07:53 PM
analyzed
Jul 13, 2026, 07:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.