VDB
GCVE-110-OSM-2026-12698
GCVE-110-OSM-2026-12698
Advisory PublishedCVSS 9.6/10
Repository compromised by the PolinRider DPRK threat actor (Lazarus / Contagious Interview cluster). PolinRider is an obfuscated JavaScript payload appended to legitimate config or source files, using v1 markers (_$_1e42 decoder + rmcej%otb% signature + shuffle seed 2857687) or v2 markers (global.i="A(8|9|10|11)-" injection prefix + shuffle seed 1111436 + Cot%3t=shtP marker). The payload uses a string-array shuffle decoder plus a require() hijack via global assignment, then fetches a second-stage loader.
Detected via OpenSourceMalware.com PolinRider GitHub hunt (2026-09-08). Repository contains the PolinRider decoder signature in 1 file(s). Injected paths: postcss.config.mjs. Content verification confirmed hex-obfuscated identifier patterns and PolinRider magic seeds in the payload where inspected. Attribution: DPRK / Lazarus / Contagious Interview campaign. Malware family: PolinRider (v1 and v2 obfuscator variants).
## Additional payload: VS Code folderOpen task with nested fake font
Malicious payload found in: `.vscode/tasks.json` and `src/app/(site)/premium-purchase/cancel/public/fonts/fa-solid-400.woff2`
- A hidden background task labeled `eslint-check` with `"runOn": "folderOpen"` runs `node ./src/app/(site)/premium-purchase/cancel/public/fonts/fa-solid-400.woff2` when the folder is opened in VS Code. The fake font is buried inside an existing app route folder rather than a top-level `public/fonts/`.
- First pushed 2026-09-21 09:47 UTC. The commit carries a maintainer's name and a 2026-06-27 date copied from an earlier commit.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,164 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.