MAL-2026-1635

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@polymarket-developers/clob-client/MAL-2026-1635.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1635
Published
2026-03-18T12:30:32Z
Modified
2026-03-23T05:38:56.728797Z
Summary
Malicious code in @polymarket-developers/clob-client (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (345ca83f0d4f9589714459a50b08e9f733a7d56bbb131b029748ad244a2d447b)

The package @polymarket-developers/clob-client was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-01046",
            "import_time": "2026-03-19T12:18:28.00794066Z",
            "sha256": "e29eb24d991ea515f487658796596a71f9423b67ca0072ff01c288de78b64fbb",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:30:32Z",
            "versions": [
                "1.0.7",
                "1.0.8",
                "1.0.9",
                "1.1.0",
                "1.1.1"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:21.716162459Z",
            "sha256": "345ca83f0d4f9589714459a50b08e9f733a7d56bbb131b029748ad244a2d447b",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "1.0.7",
                "1.0.8",
                "1.0.9",
                "1.1.0",
                "1.1.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @polymarket-developers/clob-client

Package

Name
@polymarket-developers/clob-client
View open source insights on deps.dev
Purl
pkg:npm/%40polymarket-developers/clob-client

Affected ranges

Affected versions

1.*
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@polymarket-developers/clob-client/MAL-2026-1635.json"