← Radar

Incident case file

Sign in to watch

npm Supply-Chain Campaign — 30+ Malicious DeFi/Polymarket-Themed Packages Deliver Infostealers (SM-2026-780174)

Incident date July 1, 2026

0 views

Activeoff-chain npm supply-chain attack; wallet-agnosticSupply chain attack / npm infostealer campaignCluster: NPM-SUPPLYCHAIN-2026-07

Estimated loss

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: MISSING — no attacker identity, wallet, or named threat actor publicly disclosed. Threat actors published the packages under multiple npm publisher accounts; the most concentrated distribution vector was the GitHub account 'poly-stocks' via forked repositories.

Funds moved to: MISSING — non-quantifiable. This is a credential/secrets exfiltration campaign (crypto wallet vaults, browser cookies, saved passwords, browsing history, developer credentials, shell history, password manager vaults, private keys, mnemonic phrases, and API tokens discovered in source code), not a direct on-chain fund drain. No aggregate USD loss figure has been published by SlowMist or any other tier-1 source, since losses would only materialize downstream if/when exfiltrated secrets are used
Discovery credited to SafeDep (@safedepio); detection performed by SlowMist's MistEye system. The campaign used shared C2 infrastructure, template-based droppers, and four distinct delivery methods to distribute JavaScript infostealers via 30+ DeFi-themed npm packages impersonating Polymarket tools and math/utility libraries. Example vector repository: donoaccestag/forex-mt5-trading-bot (a MetaTrader 5 forex trading bot, public on GitHub), which carries stake-math@3.5.4 as a locked dependency in

Timeline: Threat actors published 30+ DeFi-focused npm packages impersonating Polymarket tools and math libraries over an unspecified preparation period. Using shared C2 infrastructure, template-based droppers, and four separate delivery methods, they deployed JavaScript infostealers designed to harvest crypto wallets, browser data, SSH/AWS/npm secrets, Docker configs, shell history, and password-manager databases from any developer machine that ran npm install against one of the malicious packages. T0 (2026-07-01, 14:24:31 UTC): SlowMist's MistEye system detects the coordinated campaign and publishes Threat Intelligence advisory SM-2026-780174 (Critical severity), crediting SafeDep (@safedepio) for the original discovery. The advisory highlights donoaccestag/forex-mt5-trading-bot as a concrete example of a compromised distribution vector, noting its ~2.3K highly homogeneous forks (concentrated under the 'poly-stocks' account) and its locked dependency on stake-math@3.5.4. SlowMist's guidance to affected developers: immediately remove all affected npm packages; audit package.json, package-lock.json, and CI logs for any of the 30 malicious packages; treat any system that ran npm install against these packages as potentially compromised; rotate all exposed wallets, private keys, npm tokens, cloud credentials, SSH keys, and API tokens; and rebuild impacted environments from clean images. Status as of report compilation: campaign considered actively exploitable (any developer who has not yet audited/rotated credentials remains at risk), no known law-enforcement or platform-level takedown of the malicious packages confirmed, no aggregate financial loss figure published.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)