The Polymarket Trojan: Verified GitHub Org Hijacked to Distribute Crypto-Stealing Bots
ID: cd91eacc-dd02-50b8-b288-eba005581344
STIX ID: report--cd91eacc-dd02-50b8-b288-eba005581344
Feed Name: securityonline.info
Threat Score
**Executive Summary:** StepSecurity discovered a supply-chain attack in which the verified GitHub organization dev-protocol was hijacked to host malicious Polymarket trading bot repositories; typosquatted npm packages (e.g., lint-builder, ts-bign, big-nunber) install an SSH backdoor and a file/private-key stealer that exfiltrates data to C2 domains such as cloudflareguard.vercel.app while the bots continue to function normally to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
