CRITICAL
GHSA-382q-fpqh-29f7
`polymarket-clients-sdk` was removed from crates.io for malicious code
Details
It appeared to be typosquatting existing crate [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) (`clients` vs `client`) and attempting to steal credentials from local files.
The malicious crate had 6 versions published on 2026-02-05 and had been downloaded only 59 times. There were no crates depending on this crate on crates.io.
Polymarket thanks [Socket.dev](https://socket.dev/) for detecting and reporting this to the crates.io team!
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/polymarket-clients-sdk
Introduced in:
0No fixed version published yet for polymarket-clients-sdk. Pin to a known-safe version or switch to an alternative.