Security Alert: Malicious Projects Disguised as "Copy Trading Bots" on GitHub Stealing Private Keys
Jinse Finance reported that the GitHub project polymarket-copy-trading-bot has been implanted with malicious code. When the program is launched, it automatically reads the user's .env file for the wallet private key and transmits it to the hacker's server through a hidden malicious dependency package excluder-mcp-package@1.0.4, resulting in asset theft.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Indonesian Rupiah: Policy continuity offsets but cannot erase external headwinds – OCBC
Just 2,110 XRP Puts a Wallet In The TOP 10%
Update: Rocket Lab Shares Rise After Launching New Earth-Observation Satellite for Synspective
Pharvaris Chief Early Development Anne Lesage disposes of USD 765,466 in common shares
