BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Polymarket's copy-trading bot project injects malicious code to steal private keys.

2025-12-21 03:50

Odaily reports that the GitHub project polymarket-copy-trading-bot has been infected with malicious code. Upon startup, the program automatically reads the user's wallet private key from their .env file and transmits it to a hacker's server via a hidden malicious dependency package, excluder-mcp-package@1.0.4, resulting in the theft of assets.