Case · DiggingBeagle record

Fake Polymarket npm tools were built to exfiltrate wallet keys and target AI coding workflows

SafeDep found nine fake Polymarket npm packages with a shared payload that collected Ethereum private keys and sent them to attacker infrastructure when the relevant paths executed. Two names, polymarket-claude-code and polymarket-ai-agent, were tailored to AI-assisted development workflows, but public evidence does not show that an AI model hallucinated or recommended them.

Scope

Nine npm packages published on May 20, 2026 by the polymarketdev account and analyzed by SafeDep. This Case focuses on the two AI-targeted names within the shared campaign and the common private-key exfiltration behavior. It does not claim that a model-generated hallucination caused installation or that exfiltrated keys were used to move victim funds.

UnratedAI role: WITH AIAssessment method

At a glance

Claims & evidence

CLM-POLYMARKET-KEY-EXFILThe shared payload collected Ethereum private keys from an interactive prompt or local environment data and sent the raw key to attacker-controlled infrastructure.supported

Basis: reported finding

Link to claim
CLM-POLYMARKET-NINE-PACKAGESSafeDep identified nine npm packages published by the same account with a shared payload and Polymarket-themed package names.supported

Basis: reported finding

Link to claim
CLM-POLYMARKET-AI-TARGETED-NAMESSafeDep reports that the package names polymarket-claude-code and polymarket-ai-agent were selected to target developers using AI-assisted coding workflows.supported

Basis: reported finding

Link to claim
CLM-POLYMARKET-EXECUTION-PREREQUISITESafeDep reports that the packages' postinstall onboarding flow runs only in an interactive terminal; inside the login path, the code loads local environment data before prompting, so an existing PRIVATE_KEY value can be collected without the masked prompt and sent to attacker infrastructure.supported

Basis: reported finding

Link to claim

Implications

The Polymarket campaign shows why AI-oriented naming and slopsquatting should not be merged. The attacker can target developers who use coding assistants simply by publishing plausible AI-related package names; no hallucinated namespace is required. The decisive control is therefore not only better model accuracy. Package provenance, publisher history, execution approval and secret isolation still matter when the package name itself is deliberate.

The interaction with npm v12 is also bounded. Blocking unapproved lifecycle scripts can stop this specific postinstall trigger before its onboarding flow starts, but it does not make the package safe if a user or agent later approves scripts or explicitly runs package code. Separating wallet keys and signing authority from development environments limits the consequence if those earlier checks fail.

Unknowns and contradictions

  • The public evidence does not establish that a coding model or agent recommended polymarket-claude-code or polymarket-ai-agent to a victim.
  • SafeDep demonstrates private-key collection and exfiltration capability but does not document a named victim wallet transfer or quantified financial loss.
  • The public analysis does not provide a reliable victim count for the nine-package campaign.
  • The postinstall onboarding path requires an interactive terminal according to SafeDep; the public report does not establish how often real installations satisfied that prerequisite.
  • Current npm v12 blocks unapproved dependency lifecycle scripts by default, so automatic postinstall execution depends on npm version or an explicit allow decision.

Sources and citation

Material revision history

  1. Oct 7, 2026 · Canonical change recorded · new in release · revision 88