Evidence · DiggingBeagle record
Polymarket npm Packages Steal Crypto Wallet Keys
SafeDep analyzed nine npm packages published by one account to impersonate Polymarket trading tools. All nine shipped the same payload, which used a postinstall flow to solicit or read Ethereum private keys and send the raw key to an attacker-controlled Cloudflare Worker. Two package names, polymarket-claude-code and polymarket-ai-agent, were explicitly tailored to AI-assisted development workflows. The analysis demonstrates key exfiltration and AI-targeted naming, but it does not establish that a model hallucinated these package names or that a public victim lost funds.
- Published
- May 21, 2026
- Publisher
- SafeDep
Evidence record
SafeDep analyzed nine npm packages published by one account to impersonate Polymarket trading tools. All nine shipped the same payload, which used a postinstall flow to solicit or read Ethereum private keys and send the raw key to an attacker-controlled Cloudflare Worker. Two package names, polymarket-claude-code and polymarket-ai-agent, were explicitly tailored to AI-assisted development workflows. The analysis demonstrates key exfiltration and AI-targeted naming, but it does not establish that a model hallucinated these package names or that a public victim lost funds.
Claim-level citations (4)
- supportsFake Polymarket npm tools were built to exfiltrate wallet keys and target AI coding workflows: The shared payload collected Ethereum private keys from an interactive prompt or local environment data and sent the raw key to attacker-controlled infrastructure.
Sections 'Private Key Collection' and 'Data Exfiltration'.
- supportsFake Polymarket npm tools were built to exfiltrate wallet keys and target AI coding workflows: SafeDep identified nine npm packages published by the same account with a shared payload and Polymarket-themed package names.
TL;DR and 'Package Overview', including the nine-package list and shared payload hash.
- supportsFake Polymarket npm tools were built to exfiltrate wallet keys and target AI coding workflows: SafeDep reports that the package names polymarket-claude-code and polymarket-ai-agent were selected to target developers using AI-assisted coding workflows.
TL;DR, 'Package Overview' and conclusion describing the AI-tooling-specific package names.
- supportsFake Polymarket npm tools were built to exfiltrate wallet keys and target AI coding workflows: SafeDep reports that the packages' postinstall onboarding flow runs only in an interactive terminal; inside the login path, the code loads local environment data before prompting, so an existing PRIVATE_KEY value can be collected without the masked prompt and sent to attacker infrastructure.
Sections 'Execution Trigger', 'Private Key Collection' and 'Data Exfiltration', including the interactive-TTY check, .env loading and raw-key POST request.