Threats Tagged 'mal-2026-10481'
View all threats tagged with 'mal-2026-10481'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-10481'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in polymarket-mcp-v2 (npm) 0 polymarket-mcp-v2 is an information stealer and remote-access backdoor that runs automatically on `npm install`. It steals Solana keypairs, `.env` secrets and other credential files, and installs an attacker-controlled SSH key into `~/.ssh/authorized_keys`, then opens port 22 for persistent access. Any host that installed it should be treated as compromised: check `~/.ssh/authorized_keys` for an unrecognized key, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable `.env` files. The payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new C2 infrastructure. A postinstall hook (`node test.js`) requires index.js and calls two functions with no installer action. from_str_2 collects host identifiers, appends the attacker key to `~/.ssh/authorized_keys`, runs `sudo chown -R <user>:<user> ~/.ssh`, `sudo ufw enable`, `sudo ufw allow 22/tcp`, then recurses the filesystem for patterns fetched live from the C2 (`/api/scan-patterns`, `/api/block-patterns`) and uploads matches to `/api/v1`. from_str_1 does a narrower hardcoded search for id.json (Solana keypairs), config.toml and .env. The C2 (170.205.31.203:3001) served a Next.js panel titled "ENV Bot - HYPE"; a dev-mode error disclosed the operator path `C:\1\anti-server\bot-wallet-management-v1\`. --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cbccd8ee43d5fefa17eb83c5528b66a52315351a404aa54c4a32d1af0dbf238e) The package's postinstall hook loads index.js and executes routines that (1) recursively scan the install directory for id.json,.env, env, config.toml and Config.toml and POST their contents to http://170.205.31.203:3001/api/v1; (2) fetch an attacker-supplied SSH public key from http://170.205.31.203:3001/api/ssh-key, append it to ~/.ssh/authorized_keys, chown the.ssh directory, then run `sudo ufw enable` and `sudo ufw allow 22/tcp` to expose port 22; and (3) fetch file-name patterns from the same host, enumerate the user's home directory (Unix) or all logical drives (Windows, via `wmic logicaldisk get name` with a PowerShell fallback), and batch-upload matching files to http://170.205.31.203:3001/api/v1 with username and platform metadata. Module names, endpoint URLs, and API paths are hidden behind \u00xx unicode escapes and reversed-string constructions to evade static review. The behavior combines install-time credential/file exfiltration with a persistent SSH remote-access backdoor. Join the discussion | GCVE Database | 07/11/2026, 00:00:00 UTC Added: 07/14/2026, 09:21:38 UTC |
Showing 1 to 1 of 1 result