GitHub project polymarket-copy-trading-bot has been injected with malicious code. The program automatically reads the wallet private key from the user's .env file upon startup and exfiltrates it to a hacker server through a hidden malicious dependency package [email protected], resulting in asset theft.
All Comments