Malicious code executed on clone between 2026-08-29 and 2026-09-02

2026-09-02 Binds NET

https://github.com/BindsNET/bindsnet/security/advisories/GHSA-6f2q-w3r8-xxhj

Thumbnail for Malicious code executed on clone between 2026-08-29 and 2026-09-02

Attackers used compromised collaborator credentials to force-push a forged merge commit across 20 BindsNET branches, eventually introducing it into `master` through a routine Dependabot merge. A hidden Visual Studio Code task automatically ran obfuscated JavaScript disguised as a font whenever an affected repository folder was opened with Node.js available. The script retrieved a runtime second stage through Ethereum JSON-RPC endpoints and launched it as a detached process, a technique the advisory says matches the documented PolinRider pattern. The maintainers removed the injected files, restored the overwritten branches, restricted the compromised account, and enabled stronger branch protections.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cc50ab807e333f55192150c14fd0116… 2026-09-02 2026-09-02
HASH 9cb1eab50557991212b84ea52977257… 2026-09-02 2026-09-02

Related Actors

Related Reports

« Back