Polymarket's copy-trading bot project injects malicious code to steal private keys.
2025-12-21 03:50
Odaily reports that the GitHub project polymarket-copy-trading-bot has been infected with malicious code. Upon startup, the program automatically reads the user's wallet private key from their .env file and transmits it to a hacker's server via a hidden malicious dependency package, excluder-mcp-package@1.0.4, resulting in the theft of assets.
