{"id":"MAL-2026-10071","summary":"Malicious code in polymarket-kit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (63a4eba33a56521a94e4e0b3ab2923d58b0c5cd398c791e36433536591a1d6ff)\nPackage name and description advertise a 'Polymarket API SDK', but the shipped code contains no Polymarket functionality. The exported getPlugin() helper fetches JSON from https://svganchordev.net/icons/106 and passes the response's `credits` field to a Function constructor invoked with require, module, process, Buffer, and related Node globals — giving the remote endpoint arbitrary code execution in the caller's Node.js process. The Polymarket branding and 'react/helper/svg' keywords are cover for a remote fetch-and-eval backdoor. The tarball also inadvertently ships an OpenSSH ed25519 private key (`gitlab`) belonging to the author, which does not harm the installer but should be rotated by the maintainer.\n","modified":"2026-07-09T16:32:01.197051315Z","published":"2026-07-09T15:47:53Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-009235","import_time":"2026-07-09T16:20:53.269961347Z","modified_time":"2026-07-09T15:47:53Z","sha256":"63a4eba33a56521a94e4e0b3ab2923d58b0c5cd398c791e36433536591a1d6ff","source":"amazon-inspector","versions":["2.4.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/polymarket-kit/v/2.4.1"}],"affected":[{"package":{"name":"polymarket-kit","ecosystem":"npm","purl":"pkg:npm/polymarket-kit"},"versions":["2.4.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/polymarket-kit/MAL-2026-10071.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"24f9b188fee5ca7999bd67fc8c2ad3b5b7bb558ecc1db3c118783ffba5bd180c","tlsh":"dfc1616546fa21a36a67e4edf30f100271a5e2133758e971f48e42902fca668e5f24e8","path":"index.js"},{"tlsh":"1301bd01ca35dfa305d921966c798557a130dd0b4e40fc0c33860b5c1f4e1af21fe26c","path":"package.json","sha256":"33fea386bf6c9d6658a4834decfcad92630ff5452a0a48672aab9daae528735e"},{"tlsh":"aae0edb26c6d6e8a69aecef81820810a9f69f6a3493870e041e4e0852d75ea2c41c6c4","path":"gitlab","sha256":"1b518991648a8f55ae87fef0521f62db50ffec33ee374a144949bd4d6739aabb"}],"package_integrity":[{"filename":"polymarket-kit-2.4.1.tgz","hashes":{"sha1":"3c3553f8fbe482ff34893cd9fb2d7f47feeeb5c9","sha512_sri":"sha512-O0lDc8ikqlOrcfWII7cD89Nbv2F0pjjtM6pTCeNBH9rngkVUfAiFofUSTvrJEBJioM4sKnOAAUQglKHV6q8VPg=="}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}