Citing Odaily, the GitHub project polymarket-copy-trading-bot was discovered to contain malicious code. Upon launching, the program automatically reads private keys from the user's .env file and transmits them to a hacker server via the hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.
Polymarket Copy Trading Bot Project Found to Contain Malicious Code Stealing Private Keys
KuCoinFlashShare






A Polymarket copy trading bot project on GitHub was found to include malicious code stealing private keys. The bot automatically reads private keys from the .env file and sends them to a hacker server through the hidden dependency excluder-mcp-package@1.0.4. Traders are advised to avoid altcoins to watch that lack transparency. Rising trading volume on platforms highlights the need for secure tools.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.