BindsNET repository carried a forged merge commit that ran malware on folder open

2026-09-02 Isotope13

https://isotope13.ai/compendium/2026/bindsnet/

Thumbnail for BindsNET repository carried a forged merge commit that ran malware on folder open

An attacker using a BindsNET collaborator's credentials hid a malicious Visual Studio Code folder-open task inside a forged merge commit and force-pushed it across 20 branches. A routine Dependabot merge later carried the injected files into the master branch, causing an obfuscated JavaScript loader disguised as a font to execute when affected clones were opened in VS Code-compatible editors. The loader used an Ethereum wallet to discover rotating command servers and fetched an unrecoverable second stage from cleartext HTTP endpoints on port 443. The source identifies the compromise as PolinRider, a North Korean supply-chain campaign linked to the Contagious Interview and Famous Chollima activity clusters.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://166.88.73.46:443/0x/ls 2026-09-02 2026-09-06
URL http://166.88.73.46:443/0x/cls 2026-09-02 2026-09-06
IPv4 193.247.144.38 2026-09-02 2026-09-06
IPv4 23.27.13.135 2026-09-02 2026-09-06
IPv4 166.88.73.46 2026-09-02 2026-09-06
WALLET 0xa322E5f3d311D3080e6f0121063e9… 2026-09-02 2026-09-06
HASH 9cb1eab50557991212b84ea52977257… 2026-09-02 2026-09-06
IPv4 166.88.134.62 2026-07-28 2026-09-06

Related Actors

Related Reports

« Back