Golden Finance reports that the GitHub project polymarket-copy-trading-bot has been implanted with malicious code. This program automatically reads the user's wallet Private Key from the .env file upon startup and transmits it to the Hacker server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Security Alert: GitHub has seen malicious projects disguised as "copy trading Bots" that steal Private Keys.
Golden Finance reports that the GitHub project polymarket-copy-trading-bot has been implanted with malicious code. This program automatically reads the user's wallet Private Key from the .env file upon startup and transmits it to the Hacker server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.