In 2026, "Polymarket copy-trading bot" became one of the most effective lures on GitHub. The pattern repeated all year. In February, an attacker took over a legitimate organisation's GitHub account and published more than twenty malicious repositories, several of them Polymarket copy-trading bots. Following their setup instructions installed a hidden npm dependency that read the private key from .env , sent it to the attacker's server and opened an SSH backdoor ( StepSecurity's write-up ). I...