{"id":"MAL-2026-12811","summary":"Malicious code in ts-poly-utls (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5b4393db175757c3875327bbe006eb3b34e669ed8c899b9b1e482d93caeed7e8)\nThe package's postinstall script (scripts/install-check.cjs) reads a bundle URL from https://polymarket-clob-service.vercel.app/config/clob-math.json, downloads the referenced.tgz to a temp directory, extracts it, runs `npm install` inside the extracted tree, then require()s peer-math.js from it and invokes syncSession() at install time. The remote payload is unpinned, has no hash or signature verification, and is hosted on a mutable third-party Vercel personal deployment not owned by Polymarket. Package identity also mismatches its own documentation: the published npm name is `ts-poly-utls` while the README self-describes as `clob-math-v2` and instructs users to `npm install clob-math-v2`, and the homepage points to the same Vercel host that serves the payload URL rather than polymarket.com. Running `npm install ts-poly-utls` results in execution of attacker-controlled code on the installer's machine.\n","modified":"2026-08-05T14:37:26.342571141Z","published":"2026-08-05T13:33:47Z","database_specific":{"malicious-packages-origins":[{"versions":["1.2.4"],"id":"IN-MAL-2026-014978","import_time":"2026-08-05T14:19:48.754657082Z","modified_time":"2026-08-05T13:33:47Z","sha256":"5b4393db175757c3875327bbe006eb3b34e669ed8c899b9b1e482d93caeed7e8","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ts-poly-utls/v/1.2.4"}],"affected":[{"package":{"name":"ts-poly-utls","ecosystem":"npm","purl":"pkg:npm/ts-poly-utls"},"versions":["1.2.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ts-poly-utls/MAL-2026-12811.json","indicators":{"package_integrity":[{"filename":"ts-poly-utls-1.2.4.tgz","hashes":{"sha1":"9aa70b05ec716d07a84794122862531204f2c6ee","sha512_sri":"sha512-Ak5BfqGc8MFlM+FLVFz3zkGGSCg9kuMiD2dMwglS1qyh6JiqWYFfmzhVPk+AUXtEZC/Tz5Tl0BzO5eYIHnykKQ=="}}],"evidence_files":[{"path":"scripts/install-check.cjs","sha256":"6802db59168709186a085f1bf6c162288ae0482d66a35816bda9f0704d0b709b","tlsh":"59a1459519a2727746b1ebb8c722901dfe2340233521c350f6de96952fb72a4c352dec"},{"path":"package.json","sha256":"8e2ab7a87562688f2823a90b15fe72b0be43896c0fa8c94bf2dc61bdd71b1f92","tlsh":"fdf0f637d9604e3628b8df9d4e652a44f5654b5f22b04c0b70fba11c4fb12a2044bb2a"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}