Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in polymarket-mcp-v2 (npm)

0
Critical
Published: 07/11/2026 (07/11/2026, 00:00:00 UTC)
Source: GCVE Database
Product: polymarket-mcp-v2

Description

polymarket-mcp-v2 is an information stealer and remote-access backdoor that runs automatically on `npm install`. It steals Solana keypairs, `.env` secrets and other credential files, and installs an attacker-controlled SSH key into `~/.ssh/authorized_keys`, then opens port 22 for persistent access. Any host that installed it should be treated as compromised: check `~/.ssh/authorized_keys` for an unrecognized key, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable `.env` files. The payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new C2 infrastructure. A postinstall hook (`node test.js`) requires index.js and calls two functions with no installer action. from_str_2 collects host identifiers, appends the attacker key to `~/.ssh/authorized_keys`, runs `sudo chown -R <user>:<user> ~/.ssh`, `sudo ufw enable`, `sudo ufw allow 22/tcp`, then recurses the filesystem for patterns fetched live from the C2 (`/api/scan-patterns`, `/api/block-patterns`) and uploads matches to `/api/v1`. from_str_1 does a narrower hardcoded search for id.json (Solana keypairs), config.toml and .env. The C2 (170.205.31.203:3001) served a Next.js panel titled "ENV Bot - HYPE"; a dev-mode error disclosed the operator path `C:\1\anti-server\bot-wallet-management-v1\`. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cbccd8ee43d5fefa17eb83c5528b66a52315351a404aa54c4a32d1af0dbf238e) The package's postinstall hook loads index.js and executes routines that (1) recursively scan the install directory for id.json,.env, env, config.toml and Config.toml and POST their contents to http://170.205.31.203:3001/api/v1; (2) fetch an attacker-supplied SSH public key from http://170.205.31.203:3001/api/ssh-key, append it to ~/.ssh/authorized_keys, chown the.ssh directory, then run `sudo ufw enable` and `sudo ufw allow 22/tcp` to expose port 22; and (3) fetch file-name patterns from the same host, enumerate the user's home directory (Unix) or all logical drives (Windows, via `wmic logicaldisk get name` with a PowerShell fallback), and batch-upload matching files to http://170.205.31.203:3001/api/v1 with username and platform metadata. Module names, endpoint URLs, and API paths are hidden behind \u00xx unicode escapes and reversed-string constructions to evade static review. The behavior combines install-time credential/file exfiltration with a persistent SSH remote-access backdoor.

Affected software

npmghsa
polymarket-mcp-v2
Affected versions
=2.1.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:53:54 UTC

Technical Analysis

The polymarket-mcp-v2 package version 2.1.6 includes a postinstall script that performs multiple malicious actions: it recursively searches for configuration files (id.json, .env, env, config.toml, Config.toml) and sends their contents to a remote server at http://170.205.31.203:3001/api/v1. It retrieves an SSH public key from the same server, appends it to ~/.ssh/authorized_keys, changes ownership of the .ssh directory, and enables the firewall with rules to allow SSH access on port 22, effectively creating a persistent remote access backdoor. Additionally, it enumerates files matching attacker-supplied patterns across the user's home directory or all logical drives (on Windows) and uploads these files with metadata to the attacker’s server. The code uses unicode escapes and reversed strings to hide module names and URLs, complicating static analysis. This combination of credential theft and backdoor installation poses a severe threat to affected systems.

Potential Impact

Sensitive configuration files and environment data are exfiltrated to an attacker-controlled server, potentially exposing credentials and secrets. The attacker gains persistent remote access via SSH by injecting a public key and modifying firewall settings to allow inbound SSH connections. This compromises system confidentiality, integrity, and availability by enabling unauthorized access and data theft.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package version. Users should immediately remove polymarket-mcp-v2 version 2.1.6 from their environments and avoid installing it. Review systems for unauthorized SSH keys in ~/.ssh/authorized_keys and firewall rules allowing unexpected SSH access. Investigate any data exfiltration indicators and consider rotating credentials that may have been exposed. Monitor for suspicious network connections to the indicated IP address. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10481
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ffa268715ace432f7342

Added to database: 07/14/2026, 09:21:38 UTC

Last enriched: 07/14/2026, 09:53:54 UTC

Last updated: 07/31/2026, 01:38:12 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses