Crypto Wallet Drainers
npm packages using Polymarket and DeFi trading lures to steal cryptocurrency wallet private keys and drain victim funds.
discovered 2026-04-29
Objective
Steal cryptocurrency wallet keys and drain victim funds.
Packages
- npmredeem-onchain-sdkattributed-to
- npmpolymarket-trading-cliattributed-to
- npmpolymarket-terminalattributed-to
- npmpolymarket-tradeattributed-to
- npmpolymarket-auto-tradeattributed-to
- npmpolymarket-copy-tradingattributed-to
- npmpolymarket-botattributed-to
- npmpolymarket-claude-codeattributed-to
- npmpolymarket-ai-agentattributed-to
- npmpolymarket-traderattributed-to
Indicators
Techniques
- ttpT1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
- ttpT1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttpT1041 Exfiltration Over C2 Channeluses
- ttpT1552.004 Unsecured Credentials: Private Keysuses
- ttpT1552.001 Unsecured Credentials: Credentials In Filesuses
- ttpT1071.001 Application Layer Protocol: Web Protocolsuses
- ttpT1102 Web Serviceuses
- ttpT1546 Event Triggered Executionuses
