Malicious code in polygon-gamma-apis (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a49bd3ddb3340e0ef3c76465b6e275d45ddc8eecdbd742747acde8588a2018b4) [email protected] advertises itself as a 'TypeScript SDK for the Polymarket CLOB API' but ships no Polymarket API surface. The exported `getPlugin` function issues an HTTPS request to https://svganchordev.net/icons/111, reads the response's `credits` field, and passes it to `new Function('require','module',...,data.credits)` — executing attacker-controlled JavaScript inside the consumer's Node.js process with `require`, `process`, and `Buffer` available. Because the loader is passed `require`, subsequent stages can pull in native modules (dpapi, better-sqlite3, node-machine-id) to run a credential/wallet stealer. The URL is assembled piecewise (`protocol + separator + domain + path`) and surrounded by unused constants referencing legitimate CDNs (cloudflare, fastly, akamai, cloudfront, gcorelabs, cdnjs) and Font Awesome-style paths so the fetch reads as icon retrieval; an unused `setDefaultModule` referencing those CDNs is dead-code decoy. The package name and description impersonate the real @polymarket/clob-client to attract Polymarket integrators. Any consumer that imports the package and invokes the default export runs whatever JavaScript the operator of svganchordev.net serves at that moment. ## Source: ghsa-malware (bd3cc3b2775e2ba28bb5fff5c7671fad59d10810e05e72c2f5c0c8b176c1ca8c) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
AI Analysis
Technical Summary
polygon-gamma-apis versions =1.5.2 and =2.0.0 is a malicious npm package masquerading as a TypeScript SDK for the Polymarket CLOB API. Instead of providing legitimate functionality, it exports a function that fetches JavaScript code from https://svganchordev.net/icons/111 and executes it dynamically with access to Node.js internals such as require, process, and Buffer. This allows the attacker to load native modules to steal credentials and wallets. The package name and description are designed to impersonate the real @polymarket/clob-client to trick developers into installing it. The malicious code is obfuscated with decoy constants referencing legitimate CDNs and icon paths to disguise the network request as innocuous icon retrieval. Any system that installs or runs this package is at high risk of full compromise.
Potential Impact
Systems that install or run polygon-gamma-apis versions 1.5.2 or 2.0.0 are at risk of executing arbitrary attacker-controlled code with full access to Node.js runtime capabilities. This can lead to credential theft, wallet compromise, and potentially complete system takeover. The compromise is severe enough that all secrets and keys on the affected system should be considered exposed and require immediate rotation from a clean environment.
Mitigation Recommendations
No official patch or fix is available. The package should be immediately removed from all systems. Because the package executes arbitrary remote code, any system that has installed or run it should be considered fully compromised. All secrets, credentials, and keys stored on the system must be rotated from a different, uncompromised machine. Monitor for any suspicious activity related to this package and avoid installing untrusted or impersonating npm packages.
Malicious code in polygon-gamma-apis (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a49bd3ddb3340e0ef3c76465b6e275d45ddc8eecdbd742747acde8588a2018b4) [email protected] advertises itself as a 'TypeScript SDK for the Polymarket CLOB API' but ships no Polymarket API surface. The exported `getPlugin` function issues an HTTPS request to https://svganchordev.net/icons/111, reads the response's `credits` field, and passes it to `new Function('require','module',...,data.credits)` — executing attacker-controlled JavaScript inside the consumer's Node.js process with `require`, `process`, and `Buffer` available. Because the loader is passed `require`, subsequent stages can pull in native modules (dpapi, better-sqlite3, node-machine-id) to run a credential/wallet stealer. The URL is assembled piecewise (`protocol + separator + domain + path`) and surrounded by unused constants referencing legitimate CDNs (cloudflare, fastly, akamai, cloudfront, gcorelabs, cdnjs) and Font Awesome-style paths so the fetch reads as icon retrieval; an unused `setDefaultModule` referencing those CDNs is dead-code decoy. The package name and description impersonate the real @polymarket/clob-client to attract Polymarket integrators. Any consumer that imports the package and invokes the default export runs whatever JavaScript the operator of svganchordev.net serves at that moment. ## Source: ghsa-malware (bd3cc3b2775e2ba28bb5fff5c7671fad59d10810e05e72c2f5c0c8b176c1ca8c) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
polygon-gamma-apis versions =1.5.2 and =2.0.0 is a malicious npm package masquerading as a TypeScript SDK for the Polymarket CLOB API. Instead of providing legitimate functionality, it exports a function that fetches JavaScript code from https://svganchordev.net/icons/111 and executes it dynamically with access to Node.js internals such as require, process, and Buffer. This allows the attacker to load native modules to steal credentials and wallets. The package name and description are designed to impersonate the real @polymarket/clob-client to trick developers into installing it. The malicious code is obfuscated with decoy constants referencing legitimate CDNs and icon paths to disguise the network request as innocuous icon retrieval. Any system that installs or runs this package is at high risk of full compromise.
Potential Impact
Systems that install or run polygon-gamma-apis versions 1.5.2 or 2.0.0 are at risk of executing arbitrary attacker-controlled code with full access to Node.js runtime capabilities. This can lead to credential theft, wallet compromise, and potentially complete system takeover. The compromise is severe enough that all secrets and keys on the affected system should be considered exposed and require immediate rotation from a clean environment.
Mitigation Recommendations
No official patch or fix is available. The package should be immediately removed from all systems. Because the package executes arbitrary remote code, any system that has installed or run it should be considered fully compromised. All secrets, credentials, and keys stored on the system must be rotated from a different, uncompromised machine. Monitor for any suspicious activity related to this package and avoid installing untrusted or impersonating npm packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10148
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-hg4h-mv37-7x88"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520eb968715ace438f567a
Added to database: 07/11/2026, 09:36:57 UTC
Last enriched: 07/11/2026, 09:52:36 UTC
Last updated: 07/29/2026, 07:28:04 UTC
Views: 35
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.