T08 · Insecure Dependencies
- Location
skill.md:139- Finding
Unpinned Third-Party Packages Expose Wallet Secrets to Supply-Chain Risk
- Content
View full analysis
= 0.1.2`, a minimum version constraint does not ensure that the installed implementation is the version that was reviewed. These dependencies execute in the same Python process that receives: - `WALLET_PRIVATE_KEY` - `SOLANA_PRIVATE_KEY` - `AIONMARKET_API_KEY` - Derived Polymarket API credentials - Locally signed trading transactions Consequently, an unexpectedly updated or compromised package can access wallet secrets, alter destination addresses, modify signed-order parameters before signing, or submit unauthorized transactions. The audit found no evidence that the named packages are currently malicious; the vulnerability is the absence of reproducible and integrity-verified dependency controls. ### Attack Path 1. An attacker compromises a future release or distribution account for one of the dependencies, or causes an unsafe replacement package to be resolved. 2. A user follows the documented unpinned `pip install` command. 3. The mutable package version is installed and imported by the trading workflow. 4. The package executes while wallet private keys and API credentials are present in process memory or environment variables. 5. Malicious package code extracts credentials, changes transaction paramet ...[truncated 552 chars]- Remediation
View remediation
