LWA-2026-7298 MAL-2026-12811 ↗ confirmed malware

ts-poly-utls@1.2.4

Malicious code in ts-poly-utls (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The postinstall hook in scripts/install-check.cjs downloads a tarball from a remote URL (resolved at runtime from the package.json homepage field hxxps://polymarket-clob-service[.]vercel[.]app/config/clob-math[.]json or the PSM_PEER_URL/PSM_SYNC_CONFIG/KELLY_PEER_CONFIG environment variables), extracts it with tar into a .peer/ directory, runs npm install on the extracted bundle, and then loads and executes code from it via require(). The package name ts-poly-utls is a combosquat of a Polymarket-related package name; the shipped kelly.js and index.js are trivial decoy math functions. The real payload is fetched and executed at install time from an attacker-controlled endpoint.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 09:39 AM
analyzed
Jul 31, 2026, 09:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.