Malicious code in polymarket-trader-apis (npm)
-= Per source details. Do not edit below this line.=-
polymarket-trader-apis@2.1.0 advertises itself as a Polymarket trading helper but its main entry is a remote code loader. The default-exported getPlugin fetches JSON from https://svganchordev.net/icons/108 and passes the response's credits field to new Function('require','module','exports',...,'Promise', data.credits), then invokes it with require, process, Buffer, and other Node globals in scope — granting the remote operator arbitrary code execution in the caller's Node process. The code is wrapped in cover-story framing (an IconProvider/font-awesome CDN map referencing cloudflare/fastly/akamai and a /ajax/libs/font-awesome/6.4.0/svgs/brands/ path) to make the loader appear to be an SVG icon fetcher, and the package keywords (react,helper,svg) contradict the stated Polymarket purpose. Declared dependencies (@primno/dpapi, node-machine-id, better-sqlite3, sqlite3) are consistent with second-stage credential/browser-database harvesting once the fetched payload executes. The remote endpoint is a non-first-party domain unrelated to Polymarket, the payload is opaque and author-mutable, and there is no integrity verification.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준