VDB
GCVE-110-OSM-2026-12701
GCVE-110-OSM-2026-12701
Advisory PublishedCVSS 9.6/10
A legitimate repository that has been infected by PolinRider, a DPRK malware that spreads by force-pushing rewritten commits from infected developers' machines into every repository they can access. It carries a hidden VS Code task that runs a JavaScript payload disguised as a font file when the folder is opened, and the payload retrieves and runs a next-stage malware from attacker infrastructure. The repository has hosted several successive versions of the payload, including the first observed copy of a variant that uses a non-font file extension to evade detection. Anyone who has cloned or opened this repository should treat their machine as potentially compromised.
## Payload 1: VS Code folderOpen task
Malicious payload found in: `.vscode/tasks.json`
- Trigger: a hidden background task labeled `eslint-check` with `"runOn": "folderOpen"` runs the fake font file with Node when the folder is opened in VS Code: `(command -v node >/dev/null 2>&1 && node ./public/fonts/fa-solid-300.llf) || (where node >nul 2>&1 && node ./public/fonts/fa-solid-300.llf) || echo ''`.
- The file includes a `configurations` block (launch.json content) and a trailing comma, so strict JSON parsers reject it while VS Code (JSONC) still runs it.
- History: a tasks.json running `public/fonts/fa-solid-400.woff2` from 2026-03-29, one running `public/fonts/fa-solid-500.woff2` first pushed 2026-09-08 13:12 UTC, and one running `public/fonts/fa-solid-300.llf` first pushed 2026-09-28 15:09 UTC (the first observed appearance of the .llf variant anywhere).
## Payload 2: fake font file
Malicious payload found in: `public/fonts/fa-solid-300.llf` (current), previously `public/fonts/fa-solid-500.woff2` and `public/fonts/fa-solid-400.woff2`
- The "font" is obfuscated JavaScript. The current build is 32,320 bytes, starts with 421 tab characters of padding, sets build marker `global.i = 'A8'`, and uses a `_0x` string-array obfuscator. `.llf` is not a font extension, so checks limited to `.woff2` files miss it. Node runs it regardless of extension.
- The earlier 500 build was 32,006 bytes with build marker `A8-n*` and 273 tab characters of padding, and used the same wallet as the current build.
- C2: NullReceiver technique. The loader queries public Ethereum RPC endpoints (with a Blockscout indexer fallback) for the most recent transaction from a fixed attacker wallet, decodes a C2 IP address from the recipient address, and fetches the next stage from that IP over port 443. The next stage is returned Base64-encoded in a custom response header and XOR-decoded.
- Before running the second stage, the loader stores its build marker in the global `_V` and sends it to the C2 in a `Sec-V` request header, so the server knows which build is calling home.
## Persistence: auto-push tool on infected contributor machines
Malicious payload found in: unknown (runs on infected developer machines, not committed to the repository)
- The malware on an infected contributor's machine takes the newest commit on each branch, keeps its author name, email, date, and message, replaces the contents with the payload, and force-pushes the result to every branch within seconds. Commit dates in `git log` therefore do not show when the payload arrived.
- `.gitignore` gains `config.bat`, `temp_auto_push.bat`, `temp_interactive_push.bat`, and `branch_structure.json` (the auto-push tool's working files). Their presence means at least one contributor's machine is infected.
- The same .llf file was force-pushed from this account's credentials into other infected repositories within an hour of first appearing here.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.