ts-poly-utls@1.2.4
Malicious code in ts-poly-utls (npm)
Analysis
The postinstall hook in scripts/install-check.cjs downloads a tarball from a remote URL (resolved at runtime from the package.json homepage field hxxps://polymarket-clob-service[.]vercel[.]app/config/clob-math[.]json or the PSM_PEER_URL/PSM_SYNC_CONFIG/KELLY_PEER_CONFIG environment variables), extracts it with tar into a .peer/ directory, runs npm install on the extracted bundle, and then loads and executes code from it via require(). The package name ts-poly-utls is a combosquat of a Polymarket-related package name; the shipped kelly.js and index.js are trivial decoy math functions. The real payload is fetched and executed at install time from an attacker-controlled endpoint.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 09:39 AM
- analyzed
- Jul 31, 2026, 09:40 AM
Related advisories
- postcss-animate-css-vars@2.0.3
- log-min@1.0.13
- streak-metrics-math@1.0.1
- runtime-sentinel@1.0.2
- streak-math-metrics@1.0.0
- akamai-sensorv3@1.0.0
- streak-metrics-core@1.0.0
- supersig@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.