LWA-2026-6731 MAL-2026-10516 ↗ confirmed malware

polymarket-bot-logger@1.0.1

Malicious code in polymarket-bot-logger (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1102 · Web Service

Analysis

The postinstall script (scripts/install-check.cjs) fetches a JSON configuration from hxxps://jipred[.]vercel[.]app/config/clob-math.json, extracts a bundle URL from the config, downloads a .tgz archive from that URL, extracts it into a .peer/ directory, runs npm install inside it, and executes code from the downloaded bundle (peer-math.js's syncSession function). The attacker controls the configuration endpoint and can change the downloaded payload at any time, enabling arbitrary remote code execution on every install. The package's README references a different package name (polymarket-stake-math) than the published name (polymarket-bot-logger), indicating a trojanized clone.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 10:22 PM
analyzed
Jul 13, 2026, 10:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.