BindsNET repository carried a forged merge commit that ran malware on folder open
2026-09-02 • Isotope13 •
An attacker using a BindsNET collaborator's credentials hid a malicious Visual Studio Code folder-open task inside a forged merge commit and force-pushed it across 20 branches. A routine Dependabot merge later carried the injected files into the master branch, causing an obfuscated JavaScript loader disguised as a font to execute when affected clones were opened in VS Code-compatible editors. The loader used an Ethereum wallet to discover rotating command servers and fetched an unrecoverable second stage from cleartext HTTP endpoints on port 443. The source identifies the compromise as PolinRider, a North Korean supply-chain campaign linked to the Contagious Interview and Famous Chollima activity clusters.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://166.88.73.46:443/0x/ls | 2026-09-02 | 2026-09-06 |
| URL | http://166.88.73.46:443/0x/cls | 2026-09-02 | 2026-09-06 |
| IPv4 | 193.247.144.38 | 2026-09-02 | 2026-09-06 |
| IPv4 | 23.27.13.135 | 2026-09-02 | 2026-09-06 |
| IPv4 | 166.88.73.46 | 2026-09-02 | 2026-09-06 |
| WALLET | 0xa322E5f3d311D3080e6f0121063e9… | 2026-09-02 | 2026-09-06 |
| HASH | 9cb1eab50557991212b84ea52977257… | 2026-09-02 | 2026-09-06 |
| IPv4 | 166.88.134.62 | 2026-07-28 | 2026-09-06 |