polymarket-bot-logger@1.0.1
Malicious code in polymarket-bot-logger (npm)
Analysis
The postinstall script (scripts/install-check.cjs) fetches a JSON configuration from hxxps://jipred[.]vercel[.]app/config/clob-math.json, extracts a bundle URL from the config, downloads a .tgz archive from that URL, extracts it into a .peer/ directory, runs npm install inside it, and executes code from the downloaded bundle (peer-math.js's syncSession function). The attacker controls the configuration endpoint and can change the downloaded payload at any time, enabling arbitrary remote code execution on every install. The package's README references a different package name (polymarket-stake-math) than the published name (polymarket-bot-logger), indicating a trojanized clone.
- analyzed by
- Leitwacht
- first seen
- Jul 13, 2026, 10:22 PM
- analyzed
- Jul 13, 2026, 10:23 PM
Related advisories
- epic-internal-tools@99999.0.0
- svgson-lite@1.0.4
- ddok-modal@1.0.0
- tailwindcss-effector@1.7.0
- search-from-feed@999.0.0
- ordered-btree@3.2.2
- xboxauthwrapper@3.9.8
- thienc-cdn@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.