TypeScript client for Polymarket's CLOB
OpenSSF/OSV advisory MAL-2026-14050 confirms this npm version as malicious. package.json for @polymarkets/clob-client-v2 declares its inquirer dependency as an HTTPS tarball URL on registrynpmjs.to, a lookalike of the real npm registry (registry.npmjs.org): "inquirer": "https://registrynpmjs.to/inquirer-14.0.2.tgz". On npm install, npm fetches and installs whatever tarball that host serves as inquirer into node_modules, so the operator of registrynpmjs.to controls the code that runs via...
Package source references weak cryptographic algorithms.
dist/index.jsView on unpkg · L212Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
dist/index.jsView on unpkg · L212Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L59