Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @wagni_bot/polymarket (npm)

The npm package @wagni_bot/polymarket is a typosquatted credential stealer that is part of a coordinated campaign of 25 malicious packages published under the @wagni_bot scope on 2026-07-09. Each package executes a postinstall hook that exfiltrates SSH keys, cryptocurrency wallets, and .env files to a hardcoded Telegram bot.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All npm users who installed any of the 25 @wagni_bot packages during the active period (2026-07-09 onwards).
Ecosystems
Attack vectors
Affected entities
  • @wagni_bot/polymarketPolymarket SDK typosquat; part of coordinated 25-package campaign under @wagni_bot scope

The npm package @wagni_bot/polymarket is a supply-chain credential stealer disguised as a Polymarket SDK. It is one of 25 coordinated malicious packages published under the @wagni_bot npm scope on 2026-07-09.

Each package declares a postinstall lifecycle hook that executes automatically during npm install, before the package is ever imported. The hook fingerprints the host and user (hostname, user info, platform), walks the user's home directory, and reads high-value secrets including SSH private keys (~/.ssh/id_rsa), cryptocurrency wallet files, and .env files containing API keys, tokens, and seed phrases.

The collected data is JSON-encoded and exfiltrated to a hardcoded Telegram bot via the Telegram Bot API sendMessage endpoint. All error paths are swallowed to make the installation appear normal. Research confirmed the 25 packages belong to a single campaign: the payload file is byte-identical across all packages at each version, and all exfiltrate to the same Telegram bot token, indicating a single automated actor.

The packages were detected and classified on 2026-07-09 from the live npm feed. At the time of reporting, the packages remained live on npm.

Indicators of compromise

Packages
  • @wagni_bot/polymarket
Domains
  • api.telegram.org

Remediation

  • Immediately uninstall @wagni_bot/polymarket and all other packages under the @wagni_bot scope
  • Rotate all SSH keys, API keys, tokens, and cryptocurrency wallet credentials that may have been exposed
  • Review npm install logs and audit systems for the presence of @wagni_bot packages during the active period (2026-07-09 onwards)
  • Check for unauthorized access to SSH sessions, cryptocurrency wallets, and cloud/API services
  • Monitor Telegram bot activity and report the bot token to Telegram for takedown
  • Use npm audit to identify and remove any remaining malicious @wagni_bot packages from your dependency tree

Sources

  1. GitHub Advisory GHSA-46gp-xx3g-2cqr · GitHub Advisory Database

Cite this entry

"Malicious code in @wagni_bot/polymarket (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 28, 2026. https://supplychainattack.org/incident/malicious-code-in-wagni-bot-polymarket-npm-tsggsw

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @ai_/autoprefixers (npm)

    @ai_/autoprefixers is a typosquat of the legitimate autoprefixer package that executes arbitrary attacker-controlled shell commands on installation. The malicious code fetches encrypted payloads from remote C2 servers and decrypts them using a hardcoded key suffix before execution via child_process.exec.

    npmTyposquattingCompromised package
  2. resolvedcritical

    Malicious code in ethers-secure (npm)

    The npm package ethers-secure, which mimics the popular ethers library, contained malicious code that exfiltrated Ethereum private keys to an attacker-controlled server (enjbyg3xk8l.x.pipedream.net) whenever its wallet API was used. The package was identified by Amazon Inspector and credited to the OpenSSF malicious-packages project.

    npmCompromised packageTyposquatting
  3. containedcritical

    Malicious code in chain-analyze (npm)

    The npm package chain-analyze contained malicious code that executed arbitrary Node.js commands on installation. The package impersonated the official Theta blockchain SDK and used a split-package design with a dependency (chain-manager) to hide encrypted payload from scanners.

    npmCompromised packageTyposquatting
  4. containedcritical

    Malicious code in parallely (npm)

    The npm package parallely contains malicious code that impersonates the legitimate concurrently package. When invoked, it executes a dropper that downloads and runs platform-specific payloads after anti-analysis checks.

    npmCompromised packageTyposquatting