Incident case file
Sign in to watchnpm Supply-Chain Campaign — 30+ Malicious DeFi/Polymarket-Themed Packages Deliver Infostealers (SM-2026-780174)
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: MISSING — no attacker identity, wallet, or named threat actor publicly disclosed. Threat actors published the packages under multiple npm publisher accounts; the most concentrated distribution vector was the GitHub account 'poly-stocks' via forked repositories.
Timeline: Threat actors published 30+ DeFi-focused npm packages impersonating Polymarket tools and math libraries over an unspecified preparation period. Using shared C2 infrastructure, template-based droppers, and four separate delivery methods, they deployed JavaScript infostealers designed to harvest crypto wallets, browser data, SSH/AWS/npm secrets, Docker configs, shell history, and password-manager databases from any developer machine that ran npm install against one of the malicious packages. T0 (2026-07-01, 14:24:31 UTC): SlowMist's MistEye system detects the coordinated campaign and publishes Threat Intelligence advisory SM-2026-780174 (Critical severity), crediting SafeDep (@safedepio) for the original discovery. The advisory highlights donoaccestag/forex-mt5-trading-bot as a concrete example of a compromised distribution vector, noting its ~2.3K highly homogeneous forks (concentrated under the 'poly-stocks' account) and its locked dependency on stake-math@3.5.4. SlowMist's guidance to affected developers: immediately remove all affected npm packages; audit package.json, package-lock.json, and CI logs for any of the 30 malicious packages; treat any system that ran npm install against these packages as potentially compromised; rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens; and rebuild impacted environments from clean images. Status as of report compilation: campaign considered actively exploitable (any developer who has not yet audited/rotated credentials remains at risk), no known law-enforcement or platform-level takedown of the malicious packages confirmed, no aggregate financial loss figure published.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)