A fake GitHub arbitrage bot linked to 30 malicious npm packages stole wallet keys, browser passwords and developer credentials, with researchers saying at least 53 developers were exposed.
SlowMist and SafeDep flagged a supply-chain attack built around a fake GitHub repository advertising a Polymarket arbitrage bot that claimed it could generate more than $80,000 a year. Researchers said 30 malicious npm packages were spread across several accounts and tied to the repository, which drew 36 stars and 53 forks before it was exposed. The malware was hidden in a dependency called clob-client-math and ran when users executed npm install after being instructed to place a Polymarket private key in a .env file. The malware was designed to steal crypto wallet data, browser passwords and cookies, SSH keys, AWS credentials, npm and PyPI tokens, password-manager data, private keys and API tokens. SafeDep said any machine that ran npm install on the project should be treated as compromised. Researchers believe North Korean hackers are behind the operation and linked it to a broader campaign called Contagious Trader targeting crypto developers. The incident also highlights how profitable automated trading on prediction markets has made such lures more convincing. The report cited examples of real Polymarket bots that produced outsized returns, while Polymarket users have separately faced other attacks this year, including a late-June phishing scam that drained $2.94 million from at least 11 accounts.