Malicious code executed on clone between 2026-08-29 and 2026-09-02
2026-09-02 • Binds NET •
https://github.com/BindsNET/bindsnet/security/advisories/GHSA-6f2q-w3r8-xxhj
Attackers used compromised collaborator credentials to force-push a forged merge commit across 20 BindsNET branches, eventually introducing it into `master` through a routine Dependabot merge. A hidden Visual Studio Code task automatically ran obfuscated JavaScript disguised as a font whenever an affected repository folder was opened with Node.js available. The script retrieved a runtime second stage through Ethereum JSON-RPC endpoints and launched it as a detached process, a technique the advisory says matches the documented PolinRider pattern. The maintainers removed the injected files, restored the overwritten branches, restricted the compromised account, and enabled stronger branch protections.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cc50ab807e333f55192150c14fd0116… | 2026-09-02 | 2026-09-02 |
| HASH | 9cb1eab50557991212b84ea52977257… | 2026-09-02 | 2026-09-02 |