PolinRider is A/B Testing its Way Past Your Detections
2026-09-26 • Open Source Malware •
https://opensourcemalware.com/blog/polinrider-is-a-b-testing-its-way-past-your-detections
PolinRider, a DPRK-linked cluster associated with Contagious Interview activity, is testing multiple infection variants across compromised GitHub repositories rather than replacing each build in a linear sequence. An eight-month Binary-Mindz infection involved 853 force-pushes, malicious VS Code tasks, fake `.woff2` font files, executable ESLint and Prisma configurations, and repeated restoration of malware after developer cleanups. The 500 variant uses an Ethereum-based NullReceiver dead drop and reports its build marker to the C2 server, while the more heavily obfuscated 900 variant hides under a legitimate Font Awesome filename. Detection should focus on file contents, automatic folder-open tasks, repository-wide force-push patterns, executable configuration files, and infected contributor machines rather than fixed filenames or commit history alone.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fbf0e36dd7eb1e70fc4868a8d0d0cd8… | 2026-09-26 | 2026-09-26 |
| HASH | 91e334655d31f84963e6b9369d41698… | 2026-09-26 | 2026-09-26 |
| HASH | 1a21bad1df69b51efebfd2fae849ac2… | 2026-09-26 | 2026-09-26 |
| URL | https://260120.vercel.app/setti… | 2026-09-26 | 2026-09-26 |
| URL | https://260120.vercel.app/setti… | 2026-09-26 | 2026-09-26 |
| URL | https://github.com/GulamRosul/C… | 2026-09-26 | 2026-09-26 |
| URL | https://github.com/Binary-Mindz… | 2026-09-26 | 2026-09-26 |
| URL | https://github.com/Binary-Mindz… | 2026-09-26 | 2026-09-26 |
| URL | https://github.com/Binary-Mindz… | 2026-09-26 | 2026-09-26 |
| WALLET | 0xa322e5f3d311d3080e6f0121063e9… | 2026-08-02 | 2026-09-26 |