How to Investigate a GitHub Repo's Real History

2026-10-06 • Open Source Malware •

https://opensourcemalware.com/blog/how-to-investigate-a-github-repos-real-history

Thumbnail for How to Investigate a GitHub Repo's Real History

OpenSourceMalware reconstructed a DPRK-linked PolinRider compromise of the nestjsx/nest-access-control repository by comparing forged commit metadata with GitHub server events and npm publication records. Malware operating through a victim developer account replaced a legitimate signed commit on September 8, 2026, then pushed the same poisoned tree across at least 16 branches within 38 seconds. A hidden VS Code folder-open task executed JavaScript disguised as a font file, while backdated commit metadata made the injection appear to originate in December 2025. The published npm package remained clean because version 3.2.0 still referenced the legitimate pre-tampering commit.

Related Actors

Related Reports

« Back