polymarket-data @2.0.1
Vulnerability report · Last retrieved from osv.dev July 17, 2026 at 8:02 PM UTC
OSV ID
MAL-2026-5086
Ecosystem
pypi
Summary
The package attempts to exfiltrate sensitive data related to cryptocurrencies and API keys, as well as establish persistence. Likely related to 2026-05-polymarket-data-fetcher. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-05-polymarket-data Reasons (based on the campaign): - crypto-related - exfiltration-crypto - exfiltration-credentials - persistence
Source: kam193 (a690aea77d0d48fae2a4f500f434cc5d4fb5cde042b7b902b0ee647b97921dc4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.