{"id":"MAL-2026-10033","summary":"Malicious code in @wagni_bot/polymarket-sdk (npm)","details":"The npm package `@wagni_bot/polymarket-sdk` is a supply-chain credential stealer disguised as a **Polymarket** SDK. It is one member of a coordinated campaign of 25 crypto/web3 typosquat packages published under the single npm scope `@wagni_bot` on 2026-07-09.\n\nEach package declares a `postinstall` lifecycle hook (`postinstall: node postinstall.js`) that executes automatically on `npm install`, before the package is ever imported. The script fingerprints the host and user (`os.hostname()`, `os.userInfo()`, `os.platform()`), walks the user's home directory (`readdirSync`/`readFileSync`) and reads high-value secrets — SSH private keys (`~/.ssh/id_rsa`), cryptocurrency wallet files, and `.env` files (API keys, tokens, seed phrases). It then JSON-encodes the collected data and exfiltrates it to a hardcoded Telegram bot via the Telegram Bot API `sendMessage` endpoint (https://api.telegram.org/bot8804087989:AAHUia-5DCloXsg9M9QhffTsHO5J_6FAxQM/sendMessage). All error paths are swallowed so the install appears normal.\n\ncodelake Research proved the packages belong to one campaign deterministically: the payload file is byte-identical across all 25 packages at each published version (version-lockstep), and every package exfiltrates to the same Telegram bot token — a single automated actor. Detected and classified independently from the live npm feed on 2026-07-09; at the time of reporting the packages were still live on npm and none of the 25 were present in OSV or GHSA (a first-catch).\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c939d03cb15cd37cd1e4f87e913daefd7407245c771ed23bf12a712cad2c5495)\n@wagni_bot/polymarket-sdk@1.1.3 is a credential-stealing package disguised as a Polymarket SDK. index.js exports an empty object; the package ships no advertised functionality. On `npm install`, scripts.postinstall triggers postinstall.js, which: (1) walks the current working directory, the user's home directory, and common crypto-wallet paths (.ethereum,.solana,.bitcoin, Library/Ethereum) for files matching keystore/wallet/seed/mnemonic/private/.pem/.key patterns, regex-matches Ethereum private keys, BTC WIF keys, and BIP39 mnemonics, and POSTs matches to a hardcoded bare-IP endpoint; (2) reads every file in ~/.ssh (excluding known_hosts, authorized_keys, and.pub files), harvesting id_rsa/id_ed25519 private keys, and POSTs each to the same endpoint; (3) enumerates process.env, filters for keys containing PRIVATE/SECRET/TOKEN/KEY/PASSWORD/MNEMONIC/SEED/WALLET/AWS, and exfiltrates name=value pairs together with hostname, username, and cwd. All traffic is sent over plain HTTP to http://107.161.90.180:7777. The package name impersonates a legitimate Polymarket SDK to attract developers likely to have crypto keys on disk.\n","modified":"2026-08-05T06:35:55.660443176Z","published":"2026-07-09T00:00:00Z","database_specific":{"iocs":{"hashes":["sha256:80dc4a2e2947d6f2cda962927752ffb8607bc4823958c39ccc5e44d787a8abbd"],"urls":["https://api.telegram.org/bot8804087989:AAHUia-5DCloXsg9M9QhffTsHO5J_6FAxQM/sendMessage"]},"malicious-packages-origins":[{"sha256":"00ff40156e9b9ed5217299ae05d692fef75a24e5a2870b9e165166754c7df3bf","source":"amazon-inspector","versions":["1.1.5"],"id":"IN-MAL-2026-009082","import_time":"2026-07-09T16:20:39.108031402Z","modified_time":"2026-07-09T15:25:30Z"},{"versions":["1.1.1"],"id":"IN-MAL-2026-009064","import_time":"2026-07-09T16:20:37.602587472Z","modified_time":"2026-07-09T15:22:33Z","sha256":"88763b94ea857523036af8f3f4bbc7861378dc6ca961f3738435e77ee80576c0","source":"amazon-inspector"},{"id":"IN-MAL-2026-009035","import_time":"2026-07-09T16:20:34.629095579Z","modified_time":"2026-07-09T15:17:59Z","sha256":"c939d03cb15cd37cd1e4f87e913daefd7407245c771ed23bf12a712cad2c5495","source":"amazon-inspector","versions":["1.1.3"]},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-009075","import_time":"2026-07-09T16:20:38.622439325Z","modified_time":"2026-07-09T15:24:25Z","sha256":"e23d97deed586e49260f3bc22da6bbe767b9e9fa31baa6d7bef52c889762f309"},{"sha256":"1635405e118e677f9fb564c9dc43a0bc66da70dd81752bb059e90414506e3ac7","source":"amazon-inspector","versions":["1.1.4"],"id":"IN-MAL-2026-009037","import_time":"2026-07-09T16:20:34.990822311Z","modified_time":"2026-07-09T15:18:16Z"},{"versions":["1.1.0"],"id":"IN-MAL-2026-009071","import_time":"2026-07-09T16:20:38.151858142Z","modified_time":"2026-07-09T15:23:45Z","sha256":"17116c251543c98ca4c496dc6f9022df020c590561f9dd7c221b965ea90bb946","source":"amazon-inspector"},{"versions":["1.2.0"],"id":"IN-MAL-2026-009030","import_time":"2026-07-09T16:20:33.856785927Z","modified_time":"2026-07-09T15:17:11Z","sha256":"236c5163ce694ba99be29c7e4b17f70ce4488e437c08115ff66d7477527ec00f","source":"amazon-inspector"},{"import_time":"2026-08-05T06:00:55.12166246Z","modified_time":"2026-08-05T05:51:09Z","sha256":"0f055f8d70dd18b9af14efdc24a87f3c81148d88cc2ff9383c03a6176eb7c53a","source":"amazon-inspector","versions":["1.1.2"],"id":"IN-MAL-2026-013218"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.1.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.2.0"},{"type":"ADVISORY","url":"https://research.codelake.dev/advisories/clr-2026-3011-wagni-polymarket-sdk"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wagni_bot/polymarket-sdk/v/1.1.2"}],"affected":[{"package":{"name":"@wagni_bot/polymarket-sdk","ecosystem":"npm","purl":"pkg:npm/%40wagni_bot/polymarket-sdk"},"versions":["1.1.5","1.1.1","1.1.3","1.0.0","1.1.4","1.1.0","1.2.0","1.1.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wagni_bot/polymarket-sdk/MAL-2026-10033.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"3d8a59e627a451040c959870dace8fb417d1f9c55c6e2d2190637289212f8b3f","tlsh":"5c8155c4b1fa520958a341eefa5b220210717d573848e4a9fedc9f456f56240af53bfc"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-eWdNDOj7rQjIsSgXAR1nlP2VtXoP/0kG160PMWkaP0DlfS2dA7McIR/I4ZJ4yhToWWp71KSs2XRZu5fdN2yWHw==","sha1":"7e7293d4d61a85aeca67f6f232afa43ea268446a"},"filename":"polymarket-sdk-1.1.5.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"codelake Research","contact":["https://research.codelake.dev/advisories/clr-2026-3011-wagni-polymarket-sdk"],"type":"FINDER"}]}