


Perceptive Security
SOC/SIEM Consultancy

Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys
Published:
15 March 2026 at 20:59:19
Alert date:
15 March 2026 at 21:01:01
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware
The StepSecurity threat intelligence team discovered that dev-protocol, a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project, has been hijacked. The compromised organization is now being used to distribute malicious Polymarket trading bots that steal wallet keys. This represents a significant supply chain attack targeting cryptocurrency users through a trusted development platform.
Technical details
Mitigation steps:
Affected products:
GitHub
dev-protocol
Polymarket
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
