Malicious code in polymarket-mcp-v2 (npm)
polymarket-mcp-v2 is an information stealer and remote-access backdoor that runs automatically on `npm install`. It steals Solana keypairs, `.env` secrets and other credential files, and installs an attacker-controlled SSH key into `~/.ssh/authorized_keys`, then opens port 22 for persistent access. Any host that installed it should be treated as compromised: check `~/.ssh/authorized_keys` for an unrecognized key, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable `.env` files. The payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new C2 infrastructure. A postinstall hook (`node test.js`) requires index.js and calls two functions with no installer action. from_str_2 collects host identifiers, appends the attacker key to `~/.ssh/authorized_keys`, runs `sudo chown -R <user>:<user> ~/.ssh`, `sudo ufw enable`, `sudo ufw allow 22/tcp`, then recurses the filesystem for patterns fetched live from the C2 (`/api/scan-patterns`, `/api/block-patterns`) and uploads matches to `/api/v1`. from_str_1 does a narrower hardcoded search for id.json (Solana keypairs), config.toml and .env. The C2 (170.205.31.203:3001) served a Next.js panel titled "ENV Bot - HYPE"; a dev-mode error disclosed the operator path `C:\1\anti-server\bot-wallet-management-v1\`. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cbccd8ee43d5fefa17eb83c5528b66a52315351a404aa54c4a32d1af0dbf238e) The package's postinstall hook loads index.js and executes routines that (1) recursively scan the install directory for id.json,.env, env, config.toml and Config.toml and POST their contents to http://170.205.31.203:3001/api/v1; (2) fetch an attacker-supplied SSH public key from http://170.205.31.203:3001/api/ssh-key, append it to ~/.ssh/authorized_keys, chown the.ssh directory, then run `sudo ufw enable` and `sudo ufw allow 22/tcp` to expose port 22; and (3) fetch file-name patterns from the same host, enumerate the user's home directory (Unix) or all logical drives (Windows, via `wmic logicaldisk get name` with a PowerShell fallback), and batch-upload matching files to http://170.205.31.203:3001/api/v1 with username and platform metadata. Module names, endpoint URLs, and API paths are hidden behind \u00xx unicode escapes and reversed-string constructions to evade static review. The behavior combines install-time credential/file exfiltration with a persistent SSH remote-access backdoor.
AI Analysis
Technical Summary
The polymarket-mcp-v2 package version 2.1.6 includes a postinstall script that performs multiple malicious actions: it recursively searches for configuration files (id.json, .env, env, config.toml, Config.toml) and sends their contents to a remote server at http://170.205.31.203:3001/api/v1. It retrieves an SSH public key from the same server, appends it to ~/.ssh/authorized_keys, changes ownership of the .ssh directory, and enables the firewall with rules to allow SSH access on port 22, effectively creating a persistent remote access backdoor. Additionally, it enumerates files matching attacker-supplied patterns across the user's home directory or all logical drives (on Windows) and uploads these files with metadata to the attacker’s server. The code uses unicode escapes and reversed strings to hide module names and URLs, complicating static analysis. This combination of credential theft and backdoor installation poses a severe threat to affected systems.
Potential Impact
Sensitive configuration files and environment data are exfiltrated to an attacker-controlled server, potentially exposing credentials and secrets. The attacker gains persistent remote access via SSH by injecting a public key and modifying firewall settings to allow inbound SSH connections. This compromises system confidentiality, integrity, and availability by enabling unauthorized access and data theft.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package version. Users should immediately remove polymarket-mcp-v2 version 2.1.6 from their environments and avoid installing it. Review systems for unauthorized SSH keys in ~/.ssh/authorized_keys and firewall rules allowing unexpected SSH access. Investigate any data exfiltration indicators and consider rotating credentials that may have been exposed. Monitor for suspicious network connections to the indicated IP address. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Malicious code in polymarket-mcp-v2 (npm)
Description
polymarket-mcp-v2 is an information stealer and remote-access backdoor that runs automatically on `npm install`. It steals Solana keypairs, `.env` secrets and other credential files, and installs an attacker-controlled SSH key into `~/.ssh/authorized_keys`, then opens port 22 for persistent access. Any host that installed it should be treated as compromised: check `~/.ssh/authorized_keys` for an unrecognized key, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable `.env` files. The payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new C2 infrastructure. A postinstall hook (`node test.js`) requires index.js and calls two functions with no installer action. from_str_2 collects host identifiers, appends the attacker key to `~/.ssh/authorized_keys`, runs `sudo chown -R <user>:<user> ~/.ssh`, `sudo ufw enable`, `sudo ufw allow 22/tcp`, then recurses the filesystem for patterns fetched live from the C2 (`/api/scan-patterns`, `/api/block-patterns`) and uploads matches to `/api/v1`. from_str_1 does a narrower hardcoded search for id.json (Solana keypairs), config.toml and .env. The C2 (170.205.31.203:3001) served a Next.js panel titled "ENV Bot - HYPE"; a dev-mode error disclosed the operator path `C:\1\anti-server\bot-wallet-management-v1\`. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cbccd8ee43d5fefa17eb83c5528b66a52315351a404aa54c4a32d1af0dbf238e) The package's postinstall hook loads index.js and executes routines that (1) recursively scan the install directory for id.json,.env, env, config.toml and Config.toml and POST their contents to http://170.205.31.203:3001/api/v1; (2) fetch an attacker-supplied SSH public key from http://170.205.31.203:3001/api/ssh-key, append it to ~/.ssh/authorized_keys, chown the.ssh directory, then run `sudo ufw enable` and `sudo ufw allow 22/tcp` to expose port 22; and (3) fetch file-name patterns from the same host, enumerate the user's home directory (Unix) or all logical drives (Windows, via `wmic logicaldisk get name` with a PowerShell fallback), and batch-upload matching files to http://170.205.31.203:3001/api/v1 with username and platform metadata. Module names, endpoint URLs, and API paths are hidden behind \u00xx unicode escapes and reversed-string constructions to evade static review. The behavior combines install-time credential/file exfiltration with a persistent SSH remote-access backdoor.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The polymarket-mcp-v2 package version 2.1.6 includes a postinstall script that performs multiple malicious actions: it recursively searches for configuration files (id.json, .env, env, config.toml, Config.toml) and sends their contents to a remote server at http://170.205.31.203:3001/api/v1. It retrieves an SSH public key from the same server, appends it to ~/.ssh/authorized_keys, changes ownership of the .ssh directory, and enables the firewall with rules to allow SSH access on port 22, effectively creating a persistent remote access backdoor. Additionally, it enumerates files matching attacker-supplied patterns across the user's home directory or all logical drives (on Windows) and uploads these files with metadata to the attacker’s server. The code uses unicode escapes and reversed strings to hide module names and URLs, complicating static analysis. This combination of credential theft and backdoor installation poses a severe threat to affected systems.
Potential Impact
Sensitive configuration files and environment data are exfiltrated to an attacker-controlled server, potentially exposing credentials and secrets. The attacker gains persistent remote access via SSH by injecting a public key and modifying firewall settings to allow inbound SSH connections. This compromises system confidentiality, integrity, and availability by enabling unauthorized access and data theft.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package version. Users should immediately remove polymarket-mcp-v2 version 2.1.6 from their environments and avoid installing it. Review systems for unauthorized SSH keys in ~/.ssh/authorized_keys and firewall rules allowing unexpected SSH access. Investigate any data exfiltration indicators and consider rotating credentials that may have been exposed. Monitor for suspicious network connections to the indicated IP address. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10481
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a55ffa268715ace432f7342
Added to database: 07/14/2026, 09:21:38 UTC
Last enriched: 07/14/2026, 09:53:54 UTC
Last updated: 07/31/2026, 01:38:12 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.