Embedded Malicious Code Affecting github.com/mprogrammer2020/snipper-bot-uniswap package, versions >=0.0.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMPROGRAMMER2020SNIPPERBOTUNISWAP-17821155
  • published6 Jul 2026
  • disclosed4 Jul 2026
  • creditKarlo Zanki

Introduced: 4 Jul 2026

Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using github.com/mprogrammer2020/snipper-bot-uniswap altogether.

Overview

Affected versions of this package are vulnerable to Embedded Malicious Code. This package contains malicious code and was identified as part of the PolinRider supply chain campaign, linked to North Korean threat actors associated with the Contagious Interview/Famous Chollima activity cluster. The malicious code takes the form of an obfuscated JavaScript loader, hidden either inside configuration files or disguised as a fake .woff2 font file, and triggered through developer tooling. Once executed, the loader is designed to contact public blockchain RPC infrastructure (TRON, Aptos, BNB Smart Chain) to retrieve an encrypted second-stage payload, decrypt it using an embedded XOR key, and execute it via eval().

References

CVSS Base Scores

version 4.0
version 3.1