pypi

polymarket-data @2.0.1

Vulnerability report · Last retrieved from osv.dev July 17, 2026 at 8:02 PM UTC

Malicious

OSV ID

MAL-2026-5086

Ecosystem

pypi

Summary

The package attempts to exfiltrate sensitive data related to cryptocurrencies and API keys, as well as establish persistence. Likely related to 2026-05-polymarket-data-fetcher. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-polymarket-data Reasons (based on the campaign): - crypto-related - exfiltration-crypto - exfiltration-credentials - persistence

Source: kam193 (a690aea77d0d48fae2a4f500f434cc5d4fb5cde042b7b902b0ee647b97921dc4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.