VDB
Sign up
CRITICAL

GHSA-382q-fpqh-29f7

`polymarket-clients-sdk` was removed from crates.io for malicious code

Details

It appeared to be typosquatting existing crate [`polymarket-client-sdk`](https://crates.io/crates/polymarket-client-sdk) (`clients` vs `client`) and attempting to steal credentials from local files.

The malicious crate had 6 versions published on 2026-02-05 and had been downloaded only 59 times. There were no crates depending on this crate on crates.io.

Polymarket thanks [Socket.dev](https://socket.dev/) for detecting and reporting this to the crates.io team!

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/polymarket-clients-sdk
Introduced in: 0

No fixed version published yet for polymarket-clients-sdk. Pin to a known-safe version or switch to an alternative.

References