Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore

News

Stay up to date on the latest crypto trends with our expert, in-depth coverage.

banner
Flash
03:53
Malicious code implanted in polymarket copy trading project polymarket-copy-trading-bot to steal private keys
According to Odaily, the GitHub project polymarket-copy-trading-bot has been found to contain malicious code. When the program is launched, it automatically reads the user's wallet private key from the .env file and transmits it to a hacker's server via a hidden malicious dependency package, excluder-mcp-package@1.0.4, resulting in asset theft.
03:48
Security Alert: GitHub is experiencing an incident where a bot posing as a "follower" has been stealing private keys from malicious projects.
 GitHub project polymarket-copy-trading-bot has been injected with malicious code. The program automatically reads the wallet private key from the user's .env file upon startup and exfiltrates it to a hacker server through a hidden malicious dependency package [email protected], resulting in asset theft.
03:47
Security Alert: Malicious Projects Disguised as "Copy Trading Bots" on GitHub Stealing Private Keys
Jinse Finance reported that the GitHub project polymarket-copy-trading-bot has been implanted with malicious code. When the program is launched, it automatically reads the user's .env file for the wallet private key and transmits it to the hacker's server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.
News
© 2025 Bitget