Evidence · DiggingBeagle record

Polymarket npm Packages Steal Crypto Wallet Keys

SafeDep analyzed nine npm packages published by one account to impersonate Polymarket trading tools. All nine shipped the same payload, which used a postinstall flow to solicit or read Ethereum private keys and send the raw key to an attacker-controlled Cloudflare Worker. Two package names, polymarket-claude-code and polymarket-ai-agent, were explicitly tailored to AI-assisted development workflows. The analysis demonstrates key exfiltration and AI-targeted naming, but it does not establish that a model hallucinated these package names or that a public victim lost funds.

Published
May 21, 2026
Publisher
SafeDep

Evidence record

SafeDep analyzed nine npm packages published by one account to impersonate Polymarket trading tools. All nine shipped the same payload, which used a postinstall flow to solicit or read Ethereum private keys and send the raw key to an attacker-controlled Cloudflare Worker. Two package names, polymarket-claude-code and polymarket-ai-agent, were explicitly tailored to AI-assisted development workflows. The analysis demonstrates key exfiltration and AI-targeted naming, but it does not establish that a model hallucinated these package names or that a public victim lost funds.

Read the original source ↗

Claim-level citations (4)