MAL-2026-14050

    Dashboard / Malicious Package / MAL-2026-14050

    MAL-2026-14050

    Published: 14 Aug 2026Last Modified: 14 Aug 2026

    Summary: Malicious code in @polymarkets/clob-client-v2 (npm)

    Details: Source: amazon-inspector (7e06fdabf4b8b56bb40b4656a1a254801f37bef08278111f59814e375be3e7dc) package.json for @polymarkets/clob-client-v2 declares its inquirer dependency as an HTTPS tarball URL on registrynpmjs.to, a lookalike of the real npm registry (registry.npmjs.org): "inquirer": "https://registrynpmjs.to/inquirer-14.0.2.tgz". On npm install, npm fetches and installs whatever tarball that host serves as inquirer into node_modules, so the operator of registrynpmjs.to controls the code that runs via inquirer's install lifecycle and on first require. The package is also published under the scope @polymarkets, a one-character variation of the legitimate Polymarket scope @polymarket, consistent with a typosquat lure whose delivery vector is the redirected dependency.

    Affected packages

    Package

    Name: @polymarkets/clob-client-v2

    Purl: pkg:npm/%40polymarkets/clob-client-v2

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.6
    MAL-2026-14050 | CVE-DB