Security Alert: Gold Finance reports that a malicious project disguised as "copy trading Bots" has appeared on GitHub. The GitHub project polymarket-copy-trading-bot has been implanted with malicious code. When the program starts, it automatically reads the wallet Private Key from the user's .env file and transmits it to the Hacker's server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Security Alert: Gold Finance reports that a malicious project disguised as "copy trading Bots" has appeared on GitHub. The GitHub project polymarket-copy-trading-bot has been implanted with malicious code. When the program starts, it automatically reads the wallet Private Key from the user's .env file and transmits it to the Hacker's server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.