Simple Polymarket RTDS client for Chainlink TWAP prices (30s / 60s)
npm installation fetches attacker-controlled remote configuration and bundle content, installs it, then executes a module from that bundle. This is a concrete staged remote-code-execution chain.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install-check.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install-check.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install-check.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install-check.cjsView on unpkg