VDB
GCVE-110-OSM-2026-12700
GCVE-110-OSM-2026-12700
Advisory PublishedCVSS 9.6/10
A legitimate repository that has been infected by PolinRider, a DPRK malware that spreads by force-pushing rewritten commits from infected developers' machines into every repository they can access. All of its branches carry a hidden VS Code task that runs a JavaScript payload disguised as a font file when the folder is opened, plus an obfuscated payload appended to the project's ESLint config that runs whenever the config is loaded. The payload retrieves and runs a next-stage malware from attacker infrastructure. A cleanup attempt by the maintainers was overwritten by new force-pushes from infected contributors, so anyone who has cloned or opened this repository should treat their machine as potentially compromised.
## Payload 1: VS Code folderOpen task
Malicious payload found in: `.vscode/tasks.json`
- Trigger: a hidden background task labeled `eslint-check` with `"runOn": "folderOpen"` runs the fake font file with Node when the folder is opened in VS Code: `(command -v node >/dev/null 2>&1 && node ./public/fonts/fa-solid-300.llf) || (where node >nul 2>&1 && node ./public/fonts/fa-solid-300.llf) || echo ''`.
- The file includes a `configurations` block (launch.json content) and a trailing comma, so strict JSON parsers reject it while VS Code (JSONC) still runs it.
- Since 2026-09-28 the task points at `fa-solid-300.llf`. Before that it pointed at `fa-solid-500.woff2` (from 2026-09-03) and `fa-solid-400.woff2` (from 2026-04-25).
## Payload 2: fake font file
Malicious payload found in: `public/fonts/fa-solid-300.llf` (current), previously `public/fonts/fa-solid-500.woff2` and `public/fonts/fa-solid-400.woff2`. A dormant 900-variant copy sits at `src/module/content-master/category/dto/public/fonts/fa-solid-900.woff2`.
- The "font" is obfuscated JavaScript. The current build is 32,320 bytes, starts with 421 tab characters of padding, sets build marker `global.i = 'A8'`, and uses a `_0x` string-array obfuscator. `.llf` is not a font extension, so checks limited to `.woff2` files miss it. Node runs it regardless of extension. The earlier 400 payload here was a single 5,533-character line.
- C2: NullReceiver technique. The loader queries public Ethereum RPC endpoints (with a Blockscout indexer fallback) for the most recent transaction from a fixed attacker wallet, decodes a C2 IP address from the recipient address, and fetches the next stage from that IP over port 443. The next stage is returned Base64-encoded in a custom response header and XOR-decoded.
- Before running the second stage, the loader stores its build marker in the global `_V` and sends it to the C2 in a `Sec-V` request header, so the server knows which build is calling home.
- The dormant 900 variant (pushed 2026-09-25, 37,567 bytes) uses marker `global['!']='9-10094'` and a keyed shuffle cipher with no plaintext indicators.
## Payload 3: ESLint config
Malicious payload found in: `eslint.config.mjs`
- Trigger: an obfuscated single line appended after the legitimate config and pushed off-screen with padding. ESLint flat config is a JavaScript module, so `npm run lint`, pre-commit hooks, CI lint jobs, or the editor's ESLint extension run it. No VS Code task is needed.
- Uses the `global['!']` marker family. First reached this repository on 2026-04-14.
## Persistence: auto-push tool on infected contributor machines
Malicious payload found in: unknown (runs on infected developer machines, not committed to the repository)
- The malware on an infected contributor's machine takes the newest commit on each branch, keeps its author name, email, date, and message, replaces the contents with the payload, and force-pushes the result to every branch within seconds. Commit dates in `git log` therefore do not show when the payload arrived.
- `.gitignore` gains `config.bat`, `temp_auto_push.bat`, `temp_interactive_push.bat`, and `branch_structure.json` (the auto-push tool's working files). Their presence means at least one contributor's machine is infected.
- A 2026-08-28 cleanup commit titled "security: remove VS Code supply-chain malware" that deleted tasks.json was rewritten on 2026-08-30 with the task restored under the same title.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.