Malicious code in polymarket-mcp-v2 (npm)
polymarket-mcp-v2 is an information stealer and remote-access backdoor that runs automatically on npm install. It steals Solana keypairs, .env secrets and other credential files, and installs an attacker-controlled SSH key into ~/.ssh/authorized_keys, then opens port 22 for persistent access. Any host that installed it should be treated as compromised: check ~/.ssh/authorized_keys for an unrecognized key, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable .env files.
The payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new C2 infrastructure. A postinstall hook (node test.js) requires index.js and calls two functions with no installer action. from_str_2 collects host identifiers, appends the attacker key to ~/.ssh/authorized_keys, runs sudo chown -R <user>:<user> ~/.ssh, sudo ufw enable, sudo ufw allow 22/tcp, then recurses the filesystem for patterns fetched live from the C2 (/api/scan-patterns, /api/block-patterns) and uploads matches to /api/v1. from_str_1 does a narrower hardcoded search for id.json (Solana keypairs), config.toml and .env. The C2 (170.205.31.203:3001) served a Next.js panel titled "ENV Bot - HYPE"; a dev-mode error disclosed the operator path C:\1\anti-server\bot-wallet-management-v1\.
The package's postinstall hook loads index.js and executes routines that (1) recursively scan the install directory for id.json,.env, env, config.toml and Config.toml and POST their contents to http://170.205.31.203:3001/api/v1; (2) fetch an attacker-supplied SSH public key from http://170.205.31.203:3001/api/ssh-key, append it to ~/.ssh/authorized_keys, chown the.ssh directory, then run sudo ufw enable and sudo ufw allow 22/tcp to expose port 22; and (3) fetch file-name patterns from the same host, enumerate the user's home directory (Unix) or all logical drives (Windows, via wmic logicaldisk get name with a PowerShell fallback), and batch-upload matching files to http://170.205.31.203:3001/api/v1 with username and platform metadata. Module names, endpoint URLs, and API paths are hidden behind \u00xx unicode escapes and reversed-string constructions to evade static review. The behavior combines install-time credential/file exfiltration with a persistent SSH remote-access backdoor.
MAL-2026-10481 is recorded against 1 package.
Published on 11 July 2026 and last revised on 30 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
IP addresses: 170.205.31.203
URLs: http://170.205.31.203:3001/api/ssh-key http://170.205.31.203:3001/api/scan-patterns http://170.205.31.203:3001/api/block-patterns http://170.205.31.203:3001/api/v1 http://170.205.31.203:3001/dashboard
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| polymarket-mcp-v2 | — | — |
References
Free Vulnerability Check
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10481 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.