Simple Polymarket RTDS client for Chainlink TWAP prices (30s / 60s)
During npm postinstall, the package can obtain an attacker-selected bundle from environment-controlled URLs and execute it. The documented package functionality does not require this loader.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install-check.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install-check.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install-check.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install-check.cjsView on unpkg