{"id":"MAL-2026-10641","summary":"Malicious code in polygon-toolkit-validator (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f56f0404b5e3f35ed475dae417f9351d4d149e163598eb72380fb6c025099e12)\nThe package presents itself as a web3/polygon validator but its exported API silently relays caller-supplied data and generated cryptographic material to a hardcoded third-party host. The `validate(content)` export base64-encodes its input and POSTs it to https://polymarket.hanaai.online/v2 with `{action:\"validator\",content:btoa(t)}`. The `randomBytes(n)` export wraps node crypto's randomBytes and forwards the resulting hex string to the same endpoint via a `check_validator()` call before returning the bytes to the caller, so any key/IV/nonce derived from this function is disclosed to the operator of that host. The package name and bundled `web3-validator-1.0.9.tgz` file mimic the legitimate web3-validator library, consistent with a typosquat/impersonation lure. The remote endpoint is not documented or caller-configurable.\n","modified":"2026-07-15T05:20:11.727376617Z","published":"2026-07-15T03:41:32Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-010605","import_time":"2026-07-15T04:32:05.736815218Z","modified_time":"2026-07-15T03:41:32Z","sha256":"f56f0404b5e3f35ed475dae417f9351d4d149e163598eb72380fb6c025099e12","source":"amazon-inspector","versions":["1.1.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/polygon-toolkit-validator/v/1.1.2"}],"affected":[{"package":{"name":"polygon-toolkit-validator","ecosystem":"npm","purl":"pkg:npm/polygon-toolkit-validator"},"versions":["1.1.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"polygon-toolkit-validator-1.1.2.tgz","hashes":{"sha512_sri":"sha512-XPFUvICplKKtyJkTuKXYikRIGZ9/dyUkCN/WtRPrIxbWSQkHSOQExKbFBcRpnPZRGU9GkW1kYPp/erd6rF7xxQ==","sha1":"77b65374bced65d3ec9bbb64b6d96b0003bb5c63"}}],"evidence_files":[{"sha256":"c1ab545a64fc86999e171ea3429d903ebce6c47a3d55dddc8bc91807c547c75a","tlsh":"635111a338c1d5710ff058f9647b8143f1f51e1b61049995e389aca7b0f8c4c51b693d","path":"dist/index.js"},{"tlsh":"46019e34c575ca630bc412f55cba9653e5b28d1f9408bc0832c6012c8b8fbab04fc2dd","path":"package.json","sha256":"5a1e85f2b1ae2ba26cb3138cdad302f42e4974c6242711b01f712f8f1dc8167b"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/polygon-toolkit-validator/MAL-2026-10641.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}