logo

The Polymarket Trojan: Verified GitHub Org Hijacked to Distribute Crypto-Stealing Bots

ID: cd91eacc-dd02-50b8-b288-eba005581344

STIX ID: report--cd91eacc-dd02-50b8-b288-eba005581344

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** StepSecurity discovered a supply-chain attack in which the verified GitHub organization dev-protocol was hijacked to host malicious Polymarket trading bot repositories; typosquatted npm packages (e.g., lint-builder, ts-bign, big-nunber) install an SSH backdoor and a file/private-key stealer that exfiltrates data to C2 domains such as cloudflareguard.vercel.app while the bots continue to function normally to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.